CVE-2018-10177: Medium severity ibm data risk manager vulnerability
ImageMagick is vulnerable to a denial of service, caused by an error in the ReadOneMNGImage function of the coders/png.c file. By persuading a victim to open a specially-crafted mng file, a remote attacker could exploit this vulnerability to cause the application to enter into an infinite loop.
Other sources
ImageMagick through version 7.0.7-28 is vulnerable to an infinite loop in coders/png.c:ReadOneMNGImage(). An attacker could exploit this to cause a denial of service via crafted MNG file.
References: https://github.com/ImageMagick/ImageMagick/issues/1095
— Red Hat
In ImageMagick 7.0.7-28, there is an infinite loop in the ReadOneMNGImage function of the coders/png.c file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted mng file.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-10177?
CVE-2018-10177 is a vulnerability in ImageMagick that allows a remote attacker to cause a denial of service by exploiting an infinite loop in the ReadOneMNGImage function of the coders/png.c file.
How can this vulnerability be exploited?
This vulnerability can be exploited by persuading a victim to open a specially-crafted mng file.
What is the severity of CVE-2018-10177?
The severity of CVE-2018-10177 is medium with a CVSS score of 6.5.
Which software versions are affected by CVE-2018-10177?
ImageMagick 7.0.7-28 and IBM Data Risk Manager version up to 2.0.6 are affected by CVE-2018-10177.
How can I fix CVE-2018-10177?
To fix CVE-2018-10177, update to ImageMagick version 8:6.8.9.9-7ubuntu5.11 or later, or apply the relevant patch provided by your software vendor.