Memory leak in ImageMagick - CVE-2019-7395
Published: February 14, 2019
Vulnerability identifier: #VU17706
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-7395
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform DoS attack on the target system.
The vulnerability exists due a memory leak in the WritePSDChannel function, as defined in the coders/psd.c source code file. A remote attacker can trick the victim into accessing a file that submits malicious input and perform denial of service attack.
Affected software
ImageMagick
Debian Linux
Opensuse
imagemagick6 (Alpine package)
imagemagick (Debian package)
Debian Linux
Opensuse
imagemagick6 (Alpine package)
imagemagick (Debian package)
How to mitigate CVE-2019-7395
Update to version 7.0.8-25.
ImageMagick - update to 7.0.8-25
imagemagick6 (Alpine package) - update to 6.9.10.37-r0
imagemagick (Debian package) - update to 8:6.9.10.23+dfsg-2.1+deb10u1
imagemagick6 (Alpine package) - update to 6.9.10.37-r0
imagemagick (Debian package) - update to 8:6.9.10.23+dfsg-2.1+deb10u1