Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Merc1995

#39019de 53,634
7.1CVSS total
Vulnerabilidades · 1
PT-2018-13114
7.1
2018-08-21
Imagemagick · Imagemagick · CVE-2018-15607
**Name of the Vulnerable Software and Affected Versions** ImageMagick version 7.0.8-11 Q16 **Description** A tiny input file can cause a hang of several minutes, consuming CPU and memory resources, ultimately resulting in an attempted large memory allocation failure. This can be leveraged by remote attackers to cause a denial of service via a crafted file. **Recommendations** For ImageMagick version 7.0.8-11 Q16, consider restricting the processing of untrusted input files to minimize the risk of exploitation. As a temporary workaround, consider implementing resource limits to prevent excessive CPU and memory consumption. At the moment, there is no information about a newer version that contains a fix for this vulnerability.