PT-2018-3691 · Imagemagick+5 · Imagemagick+5

Cornelius Aschermann

+1

·

Published

2018-05-02

·

Updated

2021-04-28

·

CVE-2018-16749

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ImageMagick versions 7.0.7-29 and earlier
Description The issue is related to a null pointer dereference in the ReadOneJNGImage function of the coders/png.c component. This can be exploited by a remote attacker to cause a denial of service, resulting in a WriteBlob assertion failure and application exit, via a crafted file.
Recommendations For ImageMagick versions 7.0.7-29 and earlier, as a temporary workaround, consider disabling the ReadOneJNGImage function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1823
BDU:2021-03345
CESA-2020_1180
CVE-2018-16749
DLA-1530-1
DLA-2366-1
MGASA-2018-0496
OPENSUSE-SU-2018_2833-1
OPENSUSE-SU-2018_3203-1
RHSA-2020:1180
RHSA-2020_1180
SUSE-SU-2018:3095-1
SUSE-SU-2018:3269-1
SUSE-SU-2018:3348-1
USN-3785-1

Affected Products

Alt Linux
Centos
Imagemagick
Red Hat
Suse
Ubuntu