#VU21055 Use-after-free in ImageMagick - CVE-2019-15140
Published: September 11, 2019 / Updated: September 12, 2019
ImageMagick
ImageMagick.org
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system
The vulnerability exists in "ReadImage" in the "MagickCore/constitute.c" file due to a use-after-free error when the affected software does improper memory operations. A remote attacker can trick a victim to open a specially crafted file and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.