Описание
ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers can trigger the encoder failure condition to exhaust memory resources and cause denial of service.
A flaw was found in ImageMagick. A remote attacker could exploit a memory leak vulnerability in the Portable Network Graphics (PNG) encoder when it fails to write Multiple-image Network Graphics (MNG) images. This flaw allows attackers to exhaust memory resources, leading to a denial of service (DoS) condition. This issue is categorized as a memory leak (CWE-401).
Отчет
This Low impact memory leak in ImageMagick's PNG encoder, when processing Multiple-image Network Graphics (MNG) images, could lead to a denial of service. While the flaw can exhaust system memory, it requires an application to process a specially crafted MNG image, limiting the attack surface in typical Red Hat deployments.
Меры по смягчению последствий
To mitigate this use system controls (such as ulimit or container memory limits) to strictly cap the memory available to the ImageMagick process. This prevents a leak from crashing the wider system.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | ImageMagick | Out of support scope | ||
| Red Hat Enterprise Linux 7 | ImageMagick | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
3.7 Low
CVSS3
Связанные уязвимости
ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers can trigger the encoder failure condition to exhaust memory resources and cause denial of service.
ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers can trigger the encoder failure condition to exhaust memory resources and cause denial of service.
ImageMagick before 7.1.2-19 contains a memory leak vulnerability in th ...
EPSS
3.7 Low
CVSS3