CVE-2018-13153: Medium severity IBM Data Risk Manager vulnerability
A flaw was found in ImageMagick 7.0.8-4, there is a memory leak in the XMagickCommand function in MagickCore/animate.c.
References: https://github.com/ImageMagick/ImageMagick/issues/1195
Upstream Patch: https://github.com/ImageMagick/ImageMagick/commit/4ab4849d667e26df0e63ece9d63ae23bc7ab0fa1 https://github.com/ImageMagick/ImageMagick6/commit/6ce6d25b47caf9b6b2979a510b6202ce0f3dd2d4
Other sources
ImageMagick is vulnerable to a denial of service, caused by a memory leak in the XMagickCommand function in MagickCore/animate.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to consume all available memory resources.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-13153?
The severity of CVE-2018-13153 is classified as moderate due to its memory leak nature in ImageMagick.
How can I fix CVE-2018-13153?
To fix CVE-2018-13153, upgrade ImageMagick to a version higher than 7.0.8-4.
Which versions of ImageMagick are affected by CVE-2018-13153?
CVE-2018-13153 affects ImageMagick version 7.0.8-4 and earlier versions.
What type of vulnerability is CVE-2018-13153?
CVE-2018-13153 is a memory leak vulnerability found in the XMagickCommand function.
Is CVE-2018-13153 exploitable remotely?
CVE-2018-13153 is not directly exploitable remotely, but it can affect applications processing untrusted images.