PT-2018-14504 · Graphicsmagick+6 · Graphicsmagick+6

Yangming1987

·

Published

2018-10-20

·

Updated

2026-05-11

·

CVE-2018-18544

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ImageMagick versions 7.0.8 through 7.0.13 GraphicsMagick versions prior to 1.3.31
Description The issue is related to a memory leak in the WriteMSLImage function of coders/msl.c in ImageMagick and the ProcessMSLScript function of coders/msl.c in GraphicsMagick.
Recommendations For ImageMagick versions 7.0.8 through 7.0.13, update to a version outside of this range to resolve the issue. For GraphicsMagick versions prior to 1.3.31, update to version 1.3.31 or later to fix the problem. As a temporary workaround, consider restricting the use of the WriteMSLImage and ProcessMSLScript functions in coders/msl.c until a patch is available.

Exploit

Fix

Missing Release of Resource after Effective Lifetime

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2894
ALT-PU-2021-1452
CESA-2020_1180
CVE-2018-18544
MGASA-2018-0496
OPENSUSE-SU-2018:3839-1
OPENSUSE-SU-2018_3824-1
OPENSUSE-SU-2018_3827-1
OPENSUSE-SU-2018_4054-1
OPENSUSE-SU-2019:1141-1
OPENSUSE-SU-2019_1141-1
RHSA-2020:1180
RHSA-2020_1180
SUSE-SU-2018:4023-1
SUSE-SU-2018_4023-1
SUSE-SU-2019:0739-1
SUSE-SU-2019:13923-1
SUSE-SU-2019:13993-1
USN-4034-1
USN-8263-1

Affected Products

Alt Linux
Centos
Graphicsmagick
Imagemagick
Red Hat
Suse
Ubuntu