Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Mageia: 2019-0142 Moderate: ImageMagick Services Denial Threat

mageia
Calendar Grey April 10, 2019
Dist Mageia Esm H88
Revamped ImageMagick versions for Mageia address severe security vulnerabilities, mitigating risks of possible denial of service threats.
In ImageMagick 7.0.8-36 Q16, there is a memory leak in the function SVGKeyValuePairs of coders/svg.c, which allows an attacker to cause a denial of service via a crafted image file

Summary

In ImageMagick 7.0.8-36 Q16, there is a memory leak in the function SVGKeyValuePairs of coders/svg.c, which allows an attacker to cause a denial of service via a crafted image file. (CVE-2019-10649)
In ImageMagick 7.0.8-36 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, which allows an attacker to cause a denial of service or information disclosure via a crafted image file. (CVE-2019-10650)

References

- https://bugs.mageia.org/show_bug.cgi?id=24614

- https://github.com/ImageMagick/Website/blob/main/ChangeLog.md

- https://www.cve.org/CVERecord?id=CVE-2019-10649

- https://www.cve.org/CVERecord?id=CVE-2019-10650

Resolution

SRPMS

- 6/core/imagemagick-6.9.10.36-1.mga6

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 10 Apr 2019
URL: https://advisories.mageia.org/MGASA-2019-0142.html
Type: security
CVE: CVE-2019-10649, CVE-2019-10650

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here