Imagemagick · Imagemagick · CVE-2018-15607
**Name of the Vulnerable Software and Affected Versions**
ImageMagick version 7.0.8-11 Q16
**Description**
A tiny input file can cause a hang of several minutes, consuming CPU and memory resources, ultimately resulting in an attempted large memory allocation failure. This can be leveraged by remote attackers to cause a denial of service via a crafted file.
**Recommendations**
For ImageMagick version 7.0.8-11 Q16, consider restricting the processing of untrusted input files to minimize the risk of exploitation. As a temporary workaround, consider implementing resource limits to prevent excessive CPU and memory consumption. At the moment, there is no information about a newer version that contains a fix for this vulnerability.