Memory leak in ImageMagick - CVE-2018-10805

 

Memory leak in ImageMagick - CVE-2018-10805

Published: July 5, 2018


Vulnerability identifier: #VU13580
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10805
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak within ReadYCBCRImage in coders/ycbcr.c. A remote attacker can perform a denial of service attack.


Affected software

ImageMagick
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power
Opensuse
php70-pecl-imagick
php71-pecl-imagick
php72-pecl-imagick
php54-pecl-imagick
php55-pecl-imagick
php56-pecl-imagick
ImageMagick

How to mitigate CVE-2018-10805

Install update from vendor's website.

php70-pecl-imagick - update to 3.4.4-1.7
php71-pecl-imagick - update to 3.4.4-2.8
php72-pecl-imagick - update to 3.4.4-2.10
php54-pecl-imagick - update to 3.4.4-2.11
php55-pecl-imagick - update to 3.4.4-2.15
php56-pecl-imagick - update to 3.4.4-2.16
ImageMagick - update to 6.9.10.68-3.22

External References

Related Security Bulletins