CVE-2018-14435: Medium severity ibm data risk manager vulnerability
A flaw was found in ImageMagick 7.0.8-4. A memory leak in DecodeImage in coders/pcd.c.
References: https://github.com/ImageMagick/ImageMagick/issues/1193
Upstream Patch: https://github.com/ImageMagick/ImageMagick6/commit/e8f4f5e776002aa6ed490d7c6f65e10fa67359dd https://github.com/ImageMagick/ImageMagick/commit/957b6397b958a5881005df27eb97319b3175a3c9
Other sources
ImageMagick 7.0.8-4 has a memory leak in DecodeImage in coders/pcd.c.
— Launchpad
ImageMagick is vulnerable to a denial of service, caused by a memory leak in the DecodeImage function in coders/pcd.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this ImageMagick vulnerability?
The vulnerability ID of this ImageMagick vulnerability is CVE-2018-14435.
What is the title of this ImageMagick vulnerability?
The title of this ImageMagick vulnerability is 'ImageMagick 7.0.8-4 has a memory leak in DecodeImage in coders/pcd.c.'
What is the severity of CVE-2018-14435?
The severity of CVE-2018-14435 is medium.
How can I fix CVE-2018-14435 vulnerability in ImageMagick?
To fix the CVE-2018-14435 vulnerability in ImageMagick, you should update the software to version 8:6.9.7.4+dfsg-16ubuntu6.4 or later.
Are there any references related to CVE-2018-14435?
Yes, there are references related to CVE-2018-14435. You can find them at the following links: [https://github.com/ImageMagick/ImageMagick/issues/1193](https://github.com/ImageMagick/ImageMagick/issues/1193), [https://usn.ubuntu.com/3785-1/](https://usn.ubuntu.com/3785-1/), [https://launchpad.net/bugs/cve/CVE-2018-14435](https://launchpad.net/bugs/cve/CVE-2018-14435).