CVE-2018-9133: Medium severity ibm data risk manager vulnerability
A flaw was found in ImageMagick 7.0.7-26 Q16. An excessive iteration in the DecodeLabImage and EncodeLabImage functions (coders/tiff.c), which results in a hang (tens of minutes) with a tiny PoC file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tiff file.
References: https://github.com/ImageMagick/ImageMagick/issues/1072
Patch: https://github.com/ImageMagick/ImageMagick/commit/089fca04e0130549fa15f48ace3f56e30a06049a
Other sources
ImageMagick 7.0.7-26 Q16 has excessive iteration in the DecodeLabImage and EncodeLabImage functions (coders/tiff.c), which results in a hang (tens of minutes) with a tiny PoC file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tiff file.
— Launchpad
ImageMagick is vulnerable to a denial of service, caused by excessive iteration in the DecodeLabImage and EncodeLabImage functions in coders/tiff.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-9133?
CVE-2018-9133 is a vulnerability in ImageMagick version 7.0.7-26 Q16 that allows a remote attacker to cause a denial of service.
What is the severity of CVE-2018-9133?
CVE-2018-9133 has a severity rating of 6.5, which is considered medium.
How can I fix CVE-2018-9133 in ImageMagick 7.0.7-26 Q16?
To fix CVE-2018-9133 in ImageMagick 7.0.7-26 Q16, you need to apply the patch provided by IBM if you are using IBM Data Risk Manager. For other affected software, you can update to the patched versions listed in the reference URLs.
Is Ubuntu affected by CVE-2018-9133?
Yes, Ubuntu is affected by CVE-2018-9133. You can find the specific affected versions and the corresponding patched versions in the reference URLs.
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-9133?
The Common Weakness Enumeration (CWE) ID for CVE-2018-9133 is CWE-834.