Memory leak in ImageMagick - CVE-2018-11655
Published: July 5, 2018
Vulnerability identifier: #VU13582
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-11655
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the function GetImagePixelCache in MagickCore/cache.c. A remote attacker can perform a denial of service attack via a specially crafted CALS image file.
Affected software
ImageMagick
Sun ZFS Storage Appliance Kit
Oracle ZFS Storage Appliance Kit
Oracle Solaris
Opensuse
Sun ZFS Storage Appliance Kit
Oracle ZFS Storage Appliance Kit
Oracle Solaris
Opensuse
How to mitigate CVE-2018-11655
Install update from vendor's website.