CVE-2018-10804: Medium severity ibm data risk manager vulnerability
A flaw was found in ImageMagick version 7.0.7-28 contains a memory leak in WriteTIFFImage in coders/tiff.c.
References: https://github.com/ImageMagick/ImageMagick/issues/1053
Other sources
ImageMagick is vulnerable to a denial of service, caused by a memory leak in in WriteTIFFImage in coders/tiff.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause the application to enter into an infinite loop.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-10804?
CVE-2018-10804 is a vulnerability in ImageMagick version 7.0.7-28 that allows remote attackers to cause a denial of service by exploiting a memory leak in WriteTIFFImage in coders/tiff.c.
How severe is CVE-2018-10804?
CVE-2018-10804 has a severity rating of 6.5, classified as medium.
Who is affected by CVE-2018-10804?
IBM Data Risk Manager 2.0.6, ImageMagick 7.0.7-28, and certain versions of Canonical Ubuntu Linux are affected by CVE-2018-10804.
How can I fix CVE-2018-10804?
To fix CVE-2018-10804, apply the respective patches provided by IBM, update the affected versions of ImageMagick and Canonical Ubuntu Linux, or upgrade to the fixed versions of the imagemagick package for Ubuntu or Debian.
Where can I find more information about CVE-2018-10804?
You can find more information about CVE-2018-10804 on the official ImageMagick GitHub page, the Ubuntu Security Notice, and the CVE-2018-10804 bug report on Launchpad.