Описание
ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafted images, causing memory exhaustion and denial of service.
A flaw was found in ImageMagick. This memory leak vulnerability exists in multiple coders that write raw pixel data, where allocated objects are not properly freed. A remote attacker can exploit this by processing specially crafted images, leading to memory exhaustion and a denial of service.
Отчет
A memory leak exists in ImageMagick's raw pixel data coders. Processing specially crafted, untrusted images can exhaust system memory and cause a Denial of Service (DoS).
Меры по смягчению последствий
Modify the ImageMagick security policy file (policy.xml, typically located in /etc/ImageMagick-7/ or /etc/ImageMagick-6/) to disable the processing of RAW pixel data formats.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | ImageMagick | Out of support scope | ||
| Red Hat Enterprise Linux 7 | ImageMagick | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
3.7 Low
CVSS3
Связанные уязвимости
ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafted images, causing memory exhaustion and denial of service.
ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafted images, causing memory exhaustion and denial of service.
ImageMagick before 7.1.2-15 contains a memory leak vulnerability in mu ...
ImageMagick: Memory Leak in multiple coders that write raw pixel data
Уязвимость консольного графического редактора ImageMagick, связанная с отсутствием освобождения памяти после эффективного срока службы, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
3.7 Low
CVSS3