CVE-2018-14436: Medium severity ibm data risk manager vulnerability
A flaw was found in ImageMagick 7.0.8-4. A memory leak in ReadMIFFImage in coders/miff.c.
References: https://github.com/ImageMagick/ImageMagick/issues/1191
Upstream Patch: https://github.com/ImageMagick/ImageMagick6/commit/ae3eecad2f59e27123c1a6c891be75d06fc03656 https://github.com/ImageMagick/ImageMagick/commit/4b352c0be410ad900469a079e389178f878aded8
Other sources
ImageMagick 7.0.8-4 has a memory leak in ReadMIFFImage in coders/miff.c.
— Launchpad
ImageMagick is vulnerable to a denial of service, caused by a memory leak in the ReadMIFFImage function in coders/miff.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-14436?
CVE-2018-14436 is a vulnerability in ImageMagick 7.0.8-4 that causes a memory leak in the ReadMIFFImage function in coders/miff.c.
How does CVE-2018-14436 affect ImageMagick?
CVE-2018-14436 allows a remote attacker to exploit a memory leak in ImageMagick's ReadMIFFImage function, potentially causing a denial of service.
What is the severity level of CVE-2018-14436?
CVE-2018-14436 has a severity level of 6.5 (medium).
How can I fix CVE-2018-14436?
To fix CVE-2018-14436, you should update to the patched version of ImageMagick provided by your software vendor or apply the necessary security patches.
Where can I find more information about CVE-2018-14436?
You can find more information about CVE-2018-14436 on the GitHub issue page and the Ubuntu Security Notice linked in the references.