Buffer over-read in ImageMagick - CVE-2018-16413
Published: October 7, 2018
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a heap-based buffer over-read in the MagickCore/quantum-private.h in PushShortPixel() function when called from the coders/psd.c ParseImageResourceBlocks() function. A remote attacker can perform a denial of service attack with a specially crafted image file.
Affected software
imagemagick (Debian package)
imagemagick6 (Alpine package)
imagemagick (Ubuntu package)
libmagick++-dev (Ubuntu package)
libmagick++5 (Ubuntu package)
libmagickcore-dev (Ubuntu package)
libmagickcore5 (Ubuntu package)
libmagickcore5-extra (Ubuntu package)
libmagickwand-dev (Ubuntu package)
libmagickwand5 (Ubuntu package)
perlmagick (Ubuntu package)
Ubuntu
Opensuse
How to mitigate CVE-2018-16413
imagemagick6 (Alpine package) - update to 6.9.10.37-r0
imagemagick (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagick++-dev (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagick++5 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagickcore-dev (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagickcore5 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagickcore5-extra (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagickwand-dev (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagickwand5 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
perlmagick (Ubuntu package) - update to Ubuntu Pro (Infra-only)