PT-2018-2695 · Imagemagick+4 · Imagemagick+4
Published
2018-08-06
·
Updated
2020-04-08
·
CVE-2018-16642
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
ImageMagick versions 7.0.7-37
Description
The issue is related to the InsertRow function in ImageMagick, which is vulnerable to an out-of-bounds write. This can be exploited by a remote attacker using a specially crafted image file, potentially leading to a denial of service. The
InsertRow function in coders/cut.c is specifically affected.Recommendations
For ImageMagick version 7.0.7-37, consider disabling the
InsertRow function as a temporary workaround until a patch is available. Restrict access to the coders/cut.c module to minimize the risk of exploitation. Avoid using the affected function with untrusted image files until the issue is resolved.Fix
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Imagemagick
Red Hat
Suse
Ubuntu