Division by zero in ImageMagick - CVE-2019-11472
Published: April 23, 2019 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
ReadXWDImage in coders/xwd.c in the XWD image parsing component of ImageMagick 7.0.8-41 Q16 allows attackers to cause a denial-of-service (divide-by-zero error) by crafting an XWD image file in which the header indicates neither LSB first nor MSB first.
Affected software
Amazon Linux AMI
Debian Linux
Fedora
Ubuntu
Opensuse
imagemagick6 (Alpine package)
perlmagick (Ubuntu package)
libmagickwand5 (Ubuntu package)
libmagickwand-dev (Ubuntu package)
libmagickcore5-extra (Ubuntu package)
libmagickcore5 (Ubuntu package)
libmagickcore-dev (Ubuntu package)
libmagick++5 (Ubuntu package)
libmagick++-dev (Ubuntu package)
imagemagick-common (Ubuntu package)
imagemagick (Ubuntu package)
GraphicsMagick
php70-pecl-imagick
php71-pecl-imagick
php72-pecl-imagick
php54-pecl-imagick
php55-pecl-imagick
php56-pecl-imagick
imagemagick (Debian package)
ImageMagick
How to mitigate CVE-2019-11472
perlmagick (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagickwand5 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagickwand-dev (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagickcore5-extra (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagickcore5 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagickcore-dev (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagick++5 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagick++-dev (Ubuntu package) - update to Ubuntu Pro (Infra-only)
imagemagick-common (Ubuntu package) - update to Ubuntu Pro (Infra-only)
imagemagick (Ubuntu package) - update to Ubuntu Pro (Infra-only)
GraphicsMagick - addressed in versions 1.3.32-1.fc29, 1.3.32-1.fc30, 1.3.34-1.el7, 1.3.34-1.el8
php70-pecl-imagick - update to 3.4.4-1.7
php71-pecl-imagick - update to 3.4.4-2.8
php72-pecl-imagick - update to 3.4.4-2.10
php54-pecl-imagick - update to 3.4.4-2.11
php55-pecl-imagick - update to 3.4.4-2.15
php56-pecl-imagick - update to 3.4.4-2.16
imagemagick (Debian package) - update to 8:6.9.10.23+dfsg-2.1+deb10u1
ImageMagick - update to 6.9.10.68-3.22
External References
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00057.html
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00001.html
- https://github.com/ImageMagick/ImageMagick/issues/1546
- https://github.com/ImageMagick/ImageMagick6/commit/f663dfb8431c97d95682a2b533cca1c8233d21b4
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PF62B5PJA2JDUOCKJGUQO3SPL74BEYSV/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WHIKB4TP6KBJWT2UIPWL5MWMG5QXKGEJ/
- https://usn.ubuntu.com/4034-1/
- https://www.debian.org/security/2020/dsa-4712
Related Security Bulletins
- Division by zero in ImageMagick
- OpenSUSE Linux update for ImageMagick
- OpenSUSE Linux update for ImageMagick
- Division by zero in imagemagick6 (Alpine package)
- Debian update for imagemagick
- Amazon Linux AMI update for php72-pecl-imagick
- Amazon Linux AMI update for php71-pecl-imagick
- Amazon Linux AMI update for php70-pecl-imagick
- Amazon Linux AMI update for php55-pecl-imagick
- Amazon Linux AMI update for php56-pecl-imagick
- Amazon Linux AMI update for php54-pecl-imagick
- Amazon Linux AMI update for ImageMagick
- Ubuntu update for imagemagick
- Fedora 30 update for GraphicsMagick
- Fedora 29 update for GraphicsMagick
- Fedora EPEL 8 update for GraphicsMagick
- Fedora EPEL 7 update for GraphicsMagick