ALT-PU-2018-2837-1
Package ImageMagick updated to version 6.9.10.16-alt1 for branch sisyphus in task 217812.
Closed vulnerabilities
Published: 2018-12-06
BDU:2021-03459
Уязвимость компонента coders/bmp.c консольного графического редактора ImageMagick, связанная с бесконечной работой цикла, позволяющая нарушителю вызвать отказ в обслуживании
Severity: MEDIUM (6.5)
Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
References:
Published: 2018-12-26
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2018-20467
In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an infinite loop and hang, with high CPU and memory consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.
Severity: MEDIUM (6.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
References:
- openSUSE-SU-2019:1141
- openSUSE-SU-2019:1141
- openSUSE-SU-2019:1320
- openSUSE-SU-2019:1320
- 106315
- 106315
- https://github.com/ImageMagick/ImageMagick/commit/db0add932fb850d762b02604ca3053b7d7ab6deb
- https://github.com/ImageMagick/ImageMagick/commit/db0add932fb850d762b02604ca3053b7d7ab6deb
- https://github.com/ImageMagick/ImageMagick/issues/1408
- https://github.com/ImageMagick/ImageMagick/issues/1408
- [debian-lts-announce] 20200818 [SECURITY] [DLA 2333-1] imagemagick security update
- [debian-lts-announce] 20200818 [SECURITY] [DLA 2333-1] imagemagick security update
- USN-4034-1
- USN-4034-1