Resource management error in ImageMagick - CVE-2019-13137
Published: September 13, 2019
Vulnerability identifier: #VU21097
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13137
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a memory leak in the "ReadPSImage" function in the "coders/ps.c" file. A remote attacker can cause a denial of service condition on the target system.
Affected software
ImageMagick
Debian Linux
Ubuntu
Opensuse
imagemagick6 (Alpine package)
imagemagick (Ubuntu package)
imagemagick (Debian package)
Debian Linux
Ubuntu
Opensuse
imagemagick6 (Alpine package)
imagemagick (Ubuntu package)
imagemagick (Debian package)
How to mitigate CVE-2019-13137
Install updates from vendor's website.
ImageMagick - update to 7.0.8-50
imagemagick6 (Alpine package) - addressed in versions 6.9.10.55-r0, 6.9.10.56-r0, 6.9.10.68-r0
imagemagick (Ubuntu package) - addressed in versions 8:6.7.7.10-6ubuntu3.13+esm21, 8:6.8.9.9-7ubuntu5.16+esm20, 8:6.9.7.4+dfsg-16ubuntu6.15+esm12, 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm10, 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm10, 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm9, 8:7.1.2.3+dfsg1-1ubuntu0.1
imagemagick (Debian package) - update to 8:6.9.10.23+dfsg-2.1+deb10u1
imagemagick6 (Alpine package) - addressed in versions 6.9.10.55-r0, 6.9.10.56-r0, 6.9.10.68-r0
imagemagick (Ubuntu package) - addressed in versions 8:6.7.7.10-6ubuntu3.13+esm21, 8:6.8.9.9-7ubuntu5.16+esm20, 8:6.9.7.4+dfsg-16ubuntu6.15+esm12, 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm10, 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm10, 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm9, 8:7.1.2.3+dfsg1-1ubuntu0.1
imagemagick (Debian package) - update to 8:6.9.10.23+dfsg-2.1+deb10u1