Memory corruption in ImageMagick - CVE-2018-7443
Published: March 7, 2018 / Updated: March 20, 2018
Vulnerability identifier: #VU10863
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7443
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.
The weakness exists in the ReadTIFFImage function due to boundary error. A remote attacker can create a specially crafted image file, trick the victim into opening it, trigger memory corruption and cause the service to crash.
The weakness exists in the ReadTIFFImage function due to boundary error. A remote attacker can create a specially crafted image file, trick the victim into opening it, trigger memory corruption and cause the service to crash.
Affected software
ImageMagick
imagemagick6 (Alpine package)
imagemagick6 (Alpine package)
How to mitigate CVE-2018-7443
Update to version 7.0.7-26.
imagemagick6 (Alpine package) - update to 6.9.10.37-r0