Heap-based buffer overflow in ImageMagick - CVE-2019-19948
Published: January 7, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due insufficient validation of row and column sizes in the "WriteSGIImage" function of coders/sgi.c. A remote attacker can trigger heap-based buffer overflow and cause a denial of service condition on the target system.
Affected software
Amazon Linux AMI
Debian Linux
Ubuntu
Opensuse
imagemagick (Debian package)
imagemagick6 (Alpine package)
imagemagick (Alpine package)
perlmagick (Ubuntu package)
libmagickwand5 (Ubuntu package)
libmagickwand-dev (Ubuntu package)
libmagickcore5-extra (Ubuntu package)
libmagickcore5 (Ubuntu package)
libmagickcore-dev (Ubuntu package)
libmagick++5 (Ubuntu package)
libmagick++-dev (Ubuntu package)
imagemagick (Ubuntu package)
php70-pecl-imagick
php71-pecl-imagick
php72-pecl-imagick
php54-pecl-imagick
php55-pecl-imagick
php56-pecl-imagick
libmagickcore-6.q16-2 (Ubuntu package)
imagemagick-6.q16 (Ubuntu package)
libmagick++-6.q16-5v5 (Ubuntu package)
libmagickcore-6.q16-2-extra (Ubuntu package)
libmagickwand-6.q16-2 (Ubuntu package)
libmagick++-6.q16-7 (Ubuntu package)
libmagickcore-6.q16-3-extra (Ubuntu package)
libmagickcore-6.q16-3 (Ubuntu package)
libmagick++-6.q16hdri-7 (Ubuntu package)
imagemagick-6.q16hdri (Ubuntu package)
libmagickcore-6.q16hdri-3 (Ubuntu package)
libmagickcore-6.q16hdri-3-extra (Ubuntu package)
libmagickwand-6.q16-3 (Ubuntu package)
libmagickwand-6.q16hdri-3 (Ubuntu package)
libmagick++-6.q16-8 (Ubuntu package)
libmagickwand-6.q16hdri-6 (Ubuntu package)
libmagickwand-6.q16-6 (Ubuntu package)
libmagickcore-6.q16hdri-6-extra (Ubuntu package)
libmagickcore-6.q16hdri-6 (Ubuntu package)
libmagickcore-6.q16-6-extra (Ubuntu package)
libmagickcore-6.q16-6 (Ubuntu package)
libmagick++-6.q16hdri-8 (Ubuntu package)
ImageMagick
How to mitigate CVE-2019-19948
imagemagick (Debian package) - addressed in versions 8:6.9.7.4+dfsg-11+deb9u8, 8:6.9.10.23+dfsg-2.1+deb10u1
perlmagick (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagickwand5 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagickwand-dev (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagickcore5-extra (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagickcore5 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagickcore-dev (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagick++5 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagick++-dev (Ubuntu package) - update to Ubuntu Pro (Infra-only)
imagemagick (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 8:6.8.9.9-7ubuntu5.16, 8:6.9.7.4+dfsg-16ubuntu6.9, 8:6.9.10.23+dfsg-2.1ubuntu11.2, 8:6.9.10.23+dfsg-2.1ubuntu11.11, 8:6.9.10.23+dfsg-2.1ubuntu13.1
php70-pecl-imagick - update to 3.4.4-1.7
php71-pecl-imagick - update to 3.4.4-2.8
php72-pecl-imagick - update to 3.4.4-2.10
php54-pecl-imagick - update to 3.4.4-2.11
php55-pecl-imagick - update to 3.4.4-2.15
php56-pecl-imagick - update to 3.4.4-2.16
libmagickcore-6.q16-2 (Ubuntu package) - update to 8:6.8.9.9-7ubuntu5.16
imagemagick-6.q16 (Ubuntu package) - addressed in versions 8:6.8.9.9-7ubuntu5.16, 8:6.9.7.4+dfsg-16ubuntu6.9, 8:6.9.10.23+dfsg-2.1ubuntu11.2, 8:6.9.10.23+dfsg-2.1ubuntu11.11, 8:6.9.10.23+dfsg-2.1ubuntu13.1
libmagick++-6.q16-5v5 (Ubuntu package) - update to 8:6.8.9.9-7ubuntu5.16
libmagickcore-6.q16-2-extra (Ubuntu package) - update to 8:6.8.9.9-7ubuntu5.16
libmagickwand-6.q16-2 (Ubuntu package) - update to 8:6.8.9.9-7ubuntu5.16
libmagick++-6.q16-7 (Ubuntu package) - update to 8:6.9.7.4+dfsg-16ubuntu6.9
libmagickcore-6.q16-3-extra (Ubuntu package) - update to 8:6.9.7.4+dfsg-16ubuntu6.9
libmagickcore-6.q16-3 (Ubuntu package) - update to 8:6.9.7.4+dfsg-16ubuntu6.9
libmagick++-6.q16hdri-7 (Ubuntu package) - update to 8:6.9.7.4+dfsg-16ubuntu6.9
imagemagick-6.q16hdri (Ubuntu package) - addressed in versions 8:6.9.7.4+dfsg-16ubuntu6.9, 8:6.9.10.23+dfsg-2.1ubuntu11.2, 8:6.9.10.23+dfsg-2.1ubuntu13.1
libmagickcore-6.q16hdri-3 (Ubuntu package) - update to 8:6.9.7.4+dfsg-16ubuntu6.9
libmagickcore-6.q16hdri-3-extra (Ubuntu package) - update to 8:6.9.7.4+dfsg-16ubuntu6.9
libmagickwand-6.q16-3 (Ubuntu package) - update to 8:6.9.7.4+dfsg-16ubuntu6.9
libmagickwand-6.q16hdri-3 (Ubuntu package) - update to 8:6.9.7.4+dfsg-16ubuntu6.9
libmagick++-6.q16-8 (Ubuntu package) - addressed in versions 8:6.9.10.23+dfsg-2.1ubuntu11.2, 8:6.9.10.23+dfsg-2.1ubuntu11.11, 8:6.9.10.23+dfsg-2.1ubuntu13.1
libmagickwand-6.q16hdri-6 (Ubuntu package) - addressed in versions 8:6.9.10.23+dfsg-2.1ubuntu11.2, 8:6.9.10.23+dfsg-2.1ubuntu13.1
libmagickwand-6.q16-6 (Ubuntu package) - addressed in versions 8:6.9.10.23+dfsg-2.1ubuntu11.2, 8:6.9.10.23+dfsg-2.1ubuntu13.1
libmagickcore-6.q16hdri-6-extra (Ubuntu package) - addressed in versions 8:6.9.10.23+dfsg-2.1ubuntu11.2, 8:6.9.10.23+dfsg-2.1ubuntu13.1
libmagickcore-6.q16hdri-6 (Ubuntu package) - addressed in versions 8:6.9.10.23+dfsg-2.1ubuntu11.2, 8:6.9.10.23+dfsg-2.1ubuntu13.1
libmagickcore-6.q16-6-extra (Ubuntu package) - addressed in versions 8:6.9.10.23+dfsg-2.1ubuntu11.2, 8:6.9.10.23+dfsg-2.1ubuntu13.1
libmagickcore-6.q16-6 (Ubuntu package) - addressed in versions 8:6.9.10.23+dfsg-2.1ubuntu11.2, 8:6.9.10.23+dfsg-2.1ubuntu11.11, 8:6.9.10.23+dfsg-2.1ubuntu13.1
libmagick++-6.q16hdri-8 (Ubuntu package) - addressed in versions 8:6.9.10.23+dfsg-2.1ubuntu11.2, 8:6.9.10.23+dfsg-2.1ubuntu13.1
ImageMagick - update to 6.9.10.68-3.22
External References
Related Security Bulletins
- Multiple vulnerabilities in ImageMagick
- OpenSUSE Linux update for ImageMagick
- Debian update for imagemagick
- Heap-based buffer overflow in imagemagick6 (Alpine package)
- Heap-based buffer overflow in imagemagick (Alpine package)
- Debian update for imagemagick
- Amazon Linux AMI update for php72-pecl-imagick
- Amazon Linux AMI update for php71-pecl-imagick
- Amazon Linux AMI update for php70-pecl-imagick
- Amazon Linux AMI update for php55-pecl-imagick
- Amazon Linux AMI update for php56-pecl-imagick
- Amazon Linux AMI update for php54-pecl-imagick
- Amazon Linux AMI update for ImageMagick
- Ubuntu update for imagemagick
- Ubuntu update for imagemagick
- Ubuntu update for imagemagick