CVE-2018-18544: Medium severity ibm data risk manager vulnerability
A flaw was found in ImageMagick 7.0.8-13 Q16. A memory leak in the function WriteMSLImage of coders/msl.c.
References: https://github.com/ImageMagick/ImageMagick/issues/1360
Upstream Patch: https://github.com/ImageMagick/ImageMagick/commit/c9c4ef4e7ca83d8a00effd16723f37946e89fbad
Other sources
ImageMagick is vulnerable to a denial of service, caused by a memory leak in the WriteMSLImage function in coders/msl.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
There is a memory leak in the function WriteMSLImage of coders/msl.c in ImageMagick 7.0.8-13 Q16, and the function ProcessMSLScript of coders/msl.c in GraphicsMagick before 1.3.31.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2018-18544.
What is the title of this vulnerability?
The title of this vulnerability is 'There is a memory leak in the function WriteMSLImage of coders/msl.c in ImageMagick 7.0.8-13 Q16 and…'
What is the description of this vulnerability?
The description of this vulnerability is that ImageMagick is vulnerable to a denial of service, caused by a memory leak in the WriteMSLImage function in coders/msl.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
What is the severity of CVE-2018-18544?
The severity of CVE-2018-18544 is medium with a CVSS score of 6.5.
What software is affected by this vulnerability?
The affected software includes ImageMagick 7.0.8-13 Q16, IBM Data Risk Manager up to version 2.0.6, Graphicsmagick up to version 1.3.31, and openSUSE Leap 15.0.