SB2019050311 - Out-of-bounds read in imagemagick6 (Alpine package)
Published: May 3, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2019-11598)
The vulnerability allows a remote attacker to access sensitive information or cause a denial of service (DoS) condition.
The vulnerability exists due to a boundary condition in the "WritePNMImage()" function in the "coders/pnm.c" file. A remote attacker can send a specially crafted image file (related to SetGrayscaleImage in MagickCore/quantize.c.), trick the victim into opening it, trigger out-of-bounds read error, get access to sensitive information or cause a DoS condition on the targeted system.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=fa08d969d9ea76754832607a9d67a116fb77088e
- https://git.alpinelinux.org/aports/commit/?id=530a544685f085941dfc43575144a1aa5090a3e4
- https://git.alpinelinux.org/aports/commit/?id=6a183d66c7dc3dca62a642c621c62bc6455f8b87
- https://git.alpinelinux.org/aports/commit/?id=e2c99a977c70ec025f2ce7b2e89c227d7fed9ed7
- https://git.alpinelinux.org/aports/commit/?id=0f7ecd696d28f3be16555aca8525bf57ed8a0669
- https://git.alpinelinux.org/aports/commit/?id=29e36876490fbbf485171dfdfa0a8cdde53f0202
- https://git.alpinelinux.org/aports/commit/?id=30218e0b6e027c2b51d4088f0b975e8f134d0e36
- https://git.alpinelinux.org/aports/commit/?id=0bb735b52e70a294b35c638b3334bf54740cbd67
- https://git.alpinelinux.org/aports/commit/?id=b86c9d69ef22f66add28b947c238717d4e78c015
- https://git.alpinelinux.org/aports/commit/?id=baeaae173050e00e11e98128097f48855500e1a7
- https://git.alpinelinux.org/aports/commit/?id=dad39c70aeb47d2083d865a24c1a015c3aea3be4