PT-2018-3712 · Imagemagick+5 · Imagemagick+5

Yanxxdo

·

Published

2018-12-06

·

Updated

2024-08-22

·

CVE-2018-20467

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 7.0.8-16
Description The issue is related to an infinite loop in the coders/bmp.c component of ImageMagick, which can cause high CPU and memory consumption, leading to a denial of service. Remote attackers can exploit this by using a crafted file.
Recommendations For versions prior to 7.0.8-16, update to version 7.0.8-16 or later to resolve the issue. As a temporary workaround, consider restricting the use of the coders/bmp.c component to minimize the risk of exploitation.

Exploit

Fix

DoS

Infinite Loop

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2837
BDU:2021-03459
CESA-2020_1180
CVE-2018-20467
DLA-2333-1
OPENSUSE-SU-2019:1141-1
OPENSUSE-SU-2019_0016-1
OPENSUSE-SU-2019_1141-1
OPENSUSE-SU-2019_1320-1
RHSA-2020:1180
RHSA-2020_1180
SUSE-SU-2019:0739-1
SUSE-SU-2019:1033-1
SUSE-SU-2019:1033-2
SUSE-SU-2019:13993-1
SUSE-SU-2019:13995-1
SUSE-SU-2019_13995-1
USN-4034-1
USN-6980-1

Affected Products

Alt Linux
Centos
Imagemagick
Red Hat
Suse
Ubuntu