CVE-2018-12600: High severity IBM Data Risk Manager vulnerability
A flaw was found in ImageMagick 7.0.8-3 Q16, ReadDIBImage and WriteDIBImage in coders/dib.c allow attackers to cause an out of bounds write via a crafted file.
References: https://github.com/ImageMagick/ImageMagick/issues/1178
Patch: https://github.com/ImageMagick/ImageMagick6/commit/ae71c12bbaa34d942e036824ff389c22b7dacade https://github.com/ImageMagick/ImageMagick/commit/921f208c2ea3cc45847f380257f270ff424adfff
Other sources
ImageMagick is vulnerable to an out-of-bounds write, caused by an error in the ReadDIBImage and WriteDIBImage functions in coders/dib.c. By persuading a victim to open a specially-crafted file, a remote attacker could overflow a buffer and execute arbitrary code on the system.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-12600?
CVE-2018-12600 is classified as a moderate severity vulnerability allowing out-of-bounds writes in ImageMagick.
How do I fix CVE-2018-12600?
To fix CVE-2018-12600, update to the patched versions of ImageMagick as specified by your operating system's package manager.
Which versions of ImageMagick are affected by CVE-2018-12600?
CVE-2018-12600 affects ImageMagick version 7.0.8-3 and possibly earlier versions.
What impact does CVE-2018-12600 have on systems using ImageMagick?
CVE-2018-12600 can potentially allow attackers to execute arbitrary code during image processing due to an out-of-bounds write.
Is my system at risk if it uses ImageMagick?
If your system uses ImageMagick version 7.0.8-3 or earlier, it is at risk of CVE-2018-12600 and should be updated immediately.