Описание
ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.
A Denial of Service (DoS) vulnerability exists in ImageMagick. An attacker with write access to the OpenCL cache directory can exhaust system memory and crash the application by placing a maliciously crafted file.
Отчет
This vulnerability in ImageMagick is of Low impact. It requires an attacker to have local write access to the OpenCL cache directory and for OpenCL to be enabled. Under these conditions, a specially crafted XML file can cause a memory leak, leading to resource exhaustion and a denial of service over extended periods.
Меры по смягчению последствий
To mitigate this, restrict write access to the OpenCL cache directory to prevent unauthorized or malformed files from being introduced. Additionally, configure process-level memory limits (using mechanisms like ulimit, cgroups, or systemd directives) for ImageMagick to contain potential memory exhaustion and safeguard overall system stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | ImageMagick | Under investigation | ||
| Red Hat Enterprise Linux 7 | ImageMagick | Under investigation |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
1.9 Low
CVSS3
Связанные уязвимости
ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.
ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.
ImageMagick before 7.1.2-13 contains a memory leak vulnerability in Lo ...
ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.
1.9 Low
CVSS3