PT-2019-2941 · Imagemagick+4 · Imagemagick+4

·

CVE-2019-13304

·

Published

2019-07-05

·

Updated

2024-10-03

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ImageMagick versions 7.0.8-50
Description The issue is related to a buffer overflow in the WritePNMImage function in the coders/pnm.c file of the ImageMagick console graphic editor. This can be exploited by a remote attacker using a specially crafted image, potentially leading to a denial of service or the execution of arbitrary code.
Recommendations For ImageMagick version 7.0.8-50, consider disabling the WritePNMImage function in coders/pnm.c as a temporary workaround until a patch is available. Restrict the use of the ImageMagick console graphic editor to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-02916
CESA-2020_1180
CVE-2019-13304
DLA-1888-1
DSA-4712-1
DSA-4715-1
OPENSUSE-SU-2019:1983-1
OPENSUSE-SU-2019_1983-1
RHSA-2020:1180
RHSA-2020_1180
SUSE-SU-2019:2106-1
USN-4192-1
USN-7053-1

Affected Products

Centos
Imagemagick
Red Hat
Suse
Ubuntu