CVE-2018-20467: Medium severity ibm data risk manager vulnerability
A flaw was found in ImageMagick before 7.0.8-16. In coders/bmp.c, an input file can result in an infinite loop and hang, with high CPU and memory consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.
References: https://github.com/ImageMagick/ImageMagick/issues/1408
Upstream Patch: https://github.com/ImageMagick/ImageMagick/commit/db0add932fb850d762b02604ca3053b7d7ab6deb
Other sources
ImageMagick is vulnerable to a denial of service, caused by an error in coders/bmp.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause the application to enter into an infinite loop.
— IBM
In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an infinite loop and hang, with high CPU and memory consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-20467?
CVE-2018-20467 is a vulnerability in ImageMagick that can cause the application to enter into an infinite loop when opening a specially-crafted file, resulting in a denial of service.
How severe is CVE-2018-20467?
CVE-2018-20467 has a severity rating of 6.5 out of 10.
Which software versions are affected by CVE-2018-20467?
CVE-2018-20467 affects ImageMagick versions from 7.0.0-0 to 7.0.8-16.
How can I fix CVE-2018-20467?
To fix CVE-2018-20467, update ImageMagick to version 7.0.8-16 or later.
Where can I find more information about CVE-2018-20467?
You can find more information about CVE-2018-20467 at the following references: [link1], [link2], [link3].