Out-of-bounds read in ImageMagick and Debian Linux - CVE-2018-18025
Published: October 7, 2018 / Updated: December 8, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to heap-based buffer over-read in the EncodeImage function of coders/pict.c, which allows attackers to cause a denial of service via a crafted SVG image file. A remote attacker can perform a denial of service attack.
Affected software
Debian Linux
Ubuntu
imagemagick6 (Alpine package)
imagemagick (Ubuntu package)
libmagick++-dev (Ubuntu package)
libmagick++5 (Ubuntu package)
libmagickcore-dev (Ubuntu package)
libmagickcore5 (Ubuntu package)
libmagickcore5-extra (Ubuntu package)
libmagickwand-dev (Ubuntu package)
libmagickwand5 (Ubuntu package)
perlmagick (Ubuntu package)
How to mitigate CVE-2018-18025
imagemagick (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagick++-dev (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagick++5 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagickcore-dev (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagickcore5 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagickcore5-extra (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagickwand-dev (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libmagickwand5 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
perlmagick (Ubuntu package) - update to Ubuntu Pro (Infra-only)