CVE-2018-16749: Null Pointer Dereference
ImageMagick is vulnerable to a denial of service, caused by a missing NULL check in the ReadOneJNGImage function in coders/png.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
Other sources
In ImageMagick 7.0.7-29 and earlier, a missing NULL check in ReadOneJNGImage in coders/png.c allows an attacker to cause a denial of service (WriteBlob assertion failure and application exit) via a crafted file.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-16749.
What is the severity of CVE-2018-16749?
The severity of CVE-2018-16749 is medium with a CVSS score of 6.5.
What is the affected software?
The affected software is ImageMagick versions 7.0.7-29 and earlier.
How can the vulnerability be exploited?
The vulnerability can be exploited by persuading a victim to open a specially crafted file.
Is there a fix available for CVE-2018-16749?
Yes, there are patches and updates available for the affected software.