CVE-2018-16750: Medium severity IBM Data Risk Manager vulnerability
ImageMagick is vulnerable to a denial of service, caused by a missing NULL check in ReadOneJNGImage function in coders/png.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
Other sources
In ImageMagick 7.0.7-29 and earlier, a memory leak in the formatIPTCfromBuffer function in coders/meta.c was found.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-16750?
CVE-2018-16750 is a vulnerability in ImageMagick that can be exploited to cause a denial of service.
How does CVE-2018-16750 affect ImageMagick?
CVE-2018-16750 affects ImageMagick versions 7.0.7-29 and earlier, and it can cause a denial of service condition.
What is the severity of CVE-2018-16750?
CVE-2018-16750 has a severity rating of medium.
How can CVE-2018-16750 be fixed?
To fix CVE-2018-16750, you should update ImageMagick to version 8:6.9.10.2+dfsg-2 or later.
What are some references for CVE-2018-16750?
You can find more information about CVE-2018-16750 at the following links: [1] http://www.securityfocus.com/bid/108492, [2] https://github.com/ImageMagick/ImageMagick/issues/1118, [3] https://usn.ubuntu.com/3785-1/