CVE-2018-9133
30.03.2018, 08:29
ImageMagick 7.0.7-26 Q16 has excessive iteration in the DecodeLabImage and EncodeLabImage functions (coders/tiff.c), which results in a hang (tens of minutes) with a tiny PoC file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tiff file.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| imagemagick | imagemagick | 7.0.7-26:q16 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 17.10 |
| canonical | ubuntu_linux | 18.04 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| imagemagick |
|
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ImageMagick |
| ||||||||||||||||||||||
| ImageMagick-config-6-SUSE |
| ||||||||||||||||||||||
| ImageMagick-config-6-upstream |
| ||||||||||||||||||||||
| libMagick++-6_Q16-3 |
| ||||||||||||||||||||||
| libMagickCore-6_Q16-1 |
| ||||||||||||||||||||||
| libMagickCore-6_Q16-1-32bit |
| ||||||||||||||||||||||
| libMagickWand-6_Q16-1 |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| ImageMagick |
| ||
| ImageMagick-c |
| ||
| ImageMagick-devel |
| ||
| ImageMagick-doc |
| ||
| ImageMagick-perl |
| ||
| autotrace |
| ||
| autotrace-devel |
| ||
| emacs |
| ||
| emacs-common |
| ||
| emacs-el |
| ||
| emacs-filesystem |
| ||
| emacs-nox |
| ||
| emacs-terminal |
| ||
| inkscape |
| ||
| inkscape-docs |
| ||
| inkscape-view |
|
Common Weakness Enumeration
References