CVE-2018-15607
21.08.2018, 15:29
In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| imagemagick | imagemagick | 7.0.8-11:q16 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| imagemagick |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| ImageMagick |
| ||
| ImageMagick-c |
| ||
| ImageMagick-devel |
| ||
| ImageMagick-doc |
| ||
| ImageMagick-perl |
| ||
| autotrace |
| ||
| autotrace-devel |
| ||
| emacs |
| ||
| emacs-common |
| ||
| emacs-el |
| ||
| emacs-filesystem |
| ||
| emacs-nox |
| ||
| emacs-terminal |
| ||
| inkscape |
| ||
| inkscape-docs |
| ||
| inkscape-view |
|