CVE-2018-14437: Medium severity ibm data risk manager vulnerability
A flaw was found in ImageMagick 7.0.8-4. A memory leak in parse8BIM in coders/meta.c.
References: https://github.com/ImageMagick/ImageMagick/issues/1190
Upstream Patch: https://github.com/ImageMagick/ImageMagick6/commit/0812674565df667b1b3e4122ad259096de311c6c https://github.com/ImageMagick/ImageMagick/commit/082223fb992448dbb574747deac9a30f986c116e
Other sources
ImageMagick 7.0.8-4 has a memory leak in parse8BIM in coders/meta.c.
— Launchpad
ImageMagick is vulnerable to a denial of service, caused by a memory leak in the parse8BIM function in coders/meta.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-14437?
CVE-2018-14437 is a vulnerability in ImageMagick 7.0.8-4 that causes a memory leak in the parse8BIM function in coders/meta.c.
What is the severity of CVE-2018-14437?
The severity of CVE-2018-14437 is medium with a CVSS score of 6.5.
How does CVE-2018-14437 affect ImageMagick?
CVE-2018-14437 affects ImageMagick by causing a denial of service condition due to a memory leak.
How can I fix CVE-2018-14437 in ImageMagick on Ubuntu?
To fix CVE-2018-14437 in ImageMagick on Ubuntu, update to version 8:6.9.7.4+dfsg-16ubuntu6.4, 6.9.10-5, 8:6.8.9.9-7ubuntu5.13, or 8:6.7.7.10-6ubuntu3.13 depending on your Ubuntu version.
Is IBM Data Risk Manager affected by CVE-2018-14437?
Yes, IBM Data Risk Manager version up to 2.0.6 is affected by CVE-2018-14437.