CVE-2018-14434: Medium severity ibm data risk manager vulnerability
A flaw was found in ImageMagick 7.0.8-4. A memory leak for a colormap in WriteMPCImage in coders/mpc.c.
References: https://github.com/ImageMagick/ImageMagick/issues/1192
Upstream Patch: https://github.com/ImageMagick/ImageMagick/commit/98a2cceae0dceccbfe54051167c2c80be1f13c3f
Other sources
ImageMagick 7.0.8-4 has a memory leak for a colormap in WriteMPCImage in coders/mpc.c.
— Launchpad
ImageMagick is vulnerable to a denial of service, caused by a memory leak in the WriteMPCImage function in coders/mpc.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-14434?
CVE-2018-14434 is a vulnerability in ImageMagick that causes a memory leak in the WriteMPCImage function.
How severe is CVE-2018-14434?
CVE-2018-14434 has a severity score of 6.5, which is considered medium severity.
How can CVE-2018-14434 be exploited?
CVE-2018-14434 can be exploited by persuading a victim to open a specially-crafted file, which triggers the memory leak and causes a denial of service.
Which versions of ImageMagick are affected by CVE-2018-14434?
ImageMagick versions up to and including 7.0.8-4 are affected by CVE-2018-14434.
How can I fix CVE-2018-14434?
To fix CVE-2018-14434, users should update to the patched versions of ImageMagick provided by the respective vendors or use the available remedies.