PT-2016-3105 · Imagemagick+3 · Imagemagick+3

Adam Mariš

·

Published

2015-02-18

·

Updated

2020-11-16

·

CVE-2015-8959

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 6.9.0-4 Beta
Description The issue is related to the coders/dds.c component in ImageMagick, which is associated with improper system resource management. This can be exploited by a remote attacker to cause a denial of service through excessive CPU consumption by using a specially crafted DDS file.
Recommendations For versions prior to 6.9.0-4 Beta, update to version 6.9.0-4 Beta or later to resolve the issue. As a temporary workaround, consider restricting the processing of DDS files to minimize the risk of exploitation.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1188
BDU:2017-01137
CVE-2015-8959
DLA-731-1
DSA-3652-1
SUSE-SU-2016:2667-1
SUSE-SU-2016:2964-1
USN-3131-1

Affected Products

Alt Linux
Imagemagick
Suse
Ubuntu