PT-2019-5492 · Imagemagick+6 · Imagemagick+6
Bingchang Liu
+1
·
Published
2019-01-11
·
Updated
2024-10-15
·
CVE-2019-7397
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
ImageMagick versions prior to 7.0.8-25
GraphicsMagick versions prior to 1.3.32
Description
The issue is related to memory management errors in the WritePDFImage function of graphic editors ImageMagick and GraphicsMagick. Exploitation of this issue may allow a remote attacker to execute arbitrary code or cause a denial of service using a specially crafted image.
Recommendations
For ImageMagick versions prior to 7.0.8-25, update to version 7.0.8-25 or later.
For GraphicsMagick versions prior to 1.3.32, update to version 1.3.32 or later.
Exploit
Fix
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Graphicsmagick
Imagemagick
Red Hat
Suse
Ubuntu