REDHAT-BUG-1581486: Low severity imagemagick vulnerability
A flaw was found in ImageMagick 7.0.7-16 Q16 x8664 2017-12-22, an infinite loop vulnerability was found in the function ReadMIFFImage in coders/miff.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted MIFF image file.
References: https://github.com/ImageMagick/ImageMagick/issues/911
Patch: https://github.com/ImageMagick/ImageMagick/commit/7523250e2664028aa1d8f02d2d7ae49c769a851e
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1581486?
The severity of REDHAT-BUG-1581486 is categorized as a denial of service vulnerability due to CPU exhaustion.
How do I fix REDHAT-BUG-1581486?
To fix REDHAT-BUG-1581486, you should update ImageMagick to the latest version that addresses this vulnerability.
What causes the vulnerability REDHAT-BUG-1581486?
REDHAT-BUG-1581486 is caused by an infinite loop in the ReadMIFFImage function when processing crafted MIFF image files.
Who is affected by REDHAT-BUG-1581486?
Users of ImageMagick version 7.0.7-16 and earlier are affected by REDHAT-BUG-1581486.
What type of attack can REDHAT-BUG-1581486 facilitate?
REDHAT-BUG-1581486 can facilitate denial of service attacks by exhausting CPU resources.