Heap-based buffer overflow in ImageMagick - CVE-2019-19948

 

Heap-based buffer overflow in ImageMagick - CVE-2019-19948

Published: January 7, 2020


Vulnerability identifier: #VU24029
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-19948
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due insufficient validation of row and column sizes in the "WriteSGIImage" function of coders/sgi.c. A remote attacker can trigger heap-based buffer overflow and cause a denial of service condition on the target system.


Affected software

ImageMagick
Amazon Linux AMI
Debian Linux
Ubuntu
Opensuse
imagemagick (Debian package)
imagemagick6 (Alpine package)
imagemagick (Alpine package)
perlmagick (Ubuntu package)
libmagickwand5 (Ubuntu package)
libmagickwand-dev (Ubuntu package)
libmagickcore5-extra (Ubuntu package)
libmagickcore5 (Ubuntu package)
libmagickcore-dev (Ubuntu package)
libmagick++5 (Ubuntu package)
libmagick++-dev (Ubuntu package)
imagemagick (Ubuntu package)
php70-pecl-imagick
php71-pecl-imagick
php72-pecl-imagick
php54-pecl-imagick
php55-pecl-imagick
php56-pecl-imagick
libmagickcore-6.q16-2 (Ubuntu package)
imagemagick-6.q16 (Ubuntu package)
libmagick++-6.q16-5v5 (Ubuntu package)
libmagickcore-6.q16-2-extra (Ubuntu package)
libmagickwand-6.q16-2 (Ubuntu package)
libmagick++-6.q16-7 (Ubuntu package)
libmagickcore-6.q16-3-extra (Ubuntu package)
libmagickcore-6.q16-3 (Ubuntu package)
libmagick++-6.q16hdri-7 (Ubuntu package)
imagemagick-6.q16hdri (Ubuntu package)
libmagickcore-6.q16hdri-3 (Ubuntu package)
libmagickcore-6.q16hdri-3-extra (Ubuntu package)
libmagickwand-6.q16-3 (Ubuntu package)
libmagickwand-6.q16hdri-3 (Ubuntu package)
libmagick++-6.q16-8 (Ubuntu package)
libmagickwand-6.q16hdri-6 (Ubuntu package)
libmagickwand-6.q16-6 (Ubuntu package)
libmagickcore-6.q16hdri-6-extra (Ubuntu package)
libmagickcore-6.q16hdri-6 (Ubuntu package)
libmagickcore-6.q16-6-extra (Ubuntu package)
libmagickcore-6.q16-6 (Ubuntu package)
libmagick++-6.q16hdri-8 (Ubuntu package)
ImageMagick

How to mitigate CVE-2019-19948

Install updates from vendor's website.

ImageMagick - update to 7.0.8-44
imagemagick (Debian package) - addressed in versions 8:6.9.7.4+dfsg-11+deb9u8, 8:6.9.10.23+dfsg-2.1+deb10u1
perlmagick (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagickwand5 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagickwand-dev (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagickcore5-extra (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagickcore5 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagickcore-dev (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagick++5 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagick++-dev (Ubuntu package) - update to Ubuntu Pro (Infra-only)
imagemagick (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 8:6.8.9.9-7ubuntu5.16, 8:6.9.7.4+dfsg-16ubuntu6.9, 8:6.9.10.23+dfsg-2.1ubuntu11.2, 8:6.9.10.23+dfsg-2.1ubuntu11.11, 8:6.9.10.23+dfsg-2.1ubuntu13.1
php70-pecl-imagick - update to 3.4.4-1.7
php71-pecl-imagick - update to 3.4.4-2.8
php72-pecl-imagick - update to 3.4.4-2.10
php54-pecl-imagick - update to 3.4.4-2.11
php55-pecl-imagick - update to 3.4.4-2.15
php56-pecl-imagick - update to 3.4.4-2.16
libmagickcore-6.q16-2 (Ubuntu package) - update to 8:6.8.9.9-7ubuntu5.16
imagemagick-6.q16 (Ubuntu package) - addressed in versions 8:6.8.9.9-7ubuntu5.16, 8:6.9.7.4+dfsg-16ubuntu6.9, 8:6.9.10.23+dfsg-2.1ubuntu11.2, 8:6.9.10.23+dfsg-2.1ubuntu11.11, 8:6.9.10.23+dfsg-2.1ubuntu13.1
libmagick++-6.q16-5v5 (Ubuntu package) - update to 8:6.8.9.9-7ubuntu5.16
libmagickcore-6.q16-2-extra (Ubuntu package) - update to 8:6.8.9.9-7ubuntu5.16
libmagickwand-6.q16-2 (Ubuntu package) - update to 8:6.8.9.9-7ubuntu5.16
libmagick++-6.q16-7 (Ubuntu package) - update to 8:6.9.7.4+dfsg-16ubuntu6.9
libmagickcore-6.q16-3-extra (Ubuntu package) - update to 8:6.9.7.4+dfsg-16ubuntu6.9
libmagickcore-6.q16-3 (Ubuntu package) - update to 8:6.9.7.4+dfsg-16ubuntu6.9
libmagick++-6.q16hdri-7 (Ubuntu package) - update to 8:6.9.7.4+dfsg-16ubuntu6.9
imagemagick-6.q16hdri (Ubuntu package) - addressed in versions 8:6.9.7.4+dfsg-16ubuntu6.9, 8:6.9.10.23+dfsg-2.1ubuntu11.2, 8:6.9.10.23+dfsg-2.1ubuntu13.1
libmagickcore-6.q16hdri-3 (Ubuntu package) - update to 8:6.9.7.4+dfsg-16ubuntu6.9
libmagickcore-6.q16hdri-3-extra (Ubuntu package) - update to 8:6.9.7.4+dfsg-16ubuntu6.9
libmagickwand-6.q16-3 (Ubuntu package) - update to 8:6.9.7.4+dfsg-16ubuntu6.9
libmagickwand-6.q16hdri-3 (Ubuntu package) - update to 8:6.9.7.4+dfsg-16ubuntu6.9
libmagick++-6.q16-8 (Ubuntu package) - addressed in versions 8:6.9.10.23+dfsg-2.1ubuntu11.2, 8:6.9.10.23+dfsg-2.1ubuntu11.11, 8:6.9.10.23+dfsg-2.1ubuntu13.1
libmagickwand-6.q16hdri-6 (Ubuntu package) - addressed in versions 8:6.9.10.23+dfsg-2.1ubuntu11.2, 8:6.9.10.23+dfsg-2.1ubuntu13.1
libmagickwand-6.q16-6 (Ubuntu package) - addressed in versions 8:6.9.10.23+dfsg-2.1ubuntu11.2, 8:6.9.10.23+dfsg-2.1ubuntu13.1
libmagickcore-6.q16hdri-6-extra (Ubuntu package) - addressed in versions 8:6.9.10.23+dfsg-2.1ubuntu11.2, 8:6.9.10.23+dfsg-2.1ubuntu13.1
libmagickcore-6.q16hdri-6 (Ubuntu package) - addressed in versions 8:6.9.10.23+dfsg-2.1ubuntu11.2, 8:6.9.10.23+dfsg-2.1ubuntu13.1
libmagickcore-6.q16-6-extra (Ubuntu package) - addressed in versions 8:6.9.10.23+dfsg-2.1ubuntu11.2, 8:6.9.10.23+dfsg-2.1ubuntu13.1
libmagickcore-6.q16-6 (Ubuntu package) - addressed in versions 8:6.9.10.23+dfsg-2.1ubuntu11.2, 8:6.9.10.23+dfsg-2.1ubuntu11.11, 8:6.9.10.23+dfsg-2.1ubuntu13.1
libmagick++-6.q16hdri-8 (Ubuntu package) - addressed in versions 8:6.9.10.23+dfsg-2.1ubuntu11.2, 8:6.9.10.23+dfsg-2.1ubuntu13.1
ImageMagick - update to 6.9.10.68-3.22

External References

Related Security Bulletins