CVE-2019-10650: High severity ibm data risk manager vulnerability
ImageMagick is vulnerable to a denial of service, caused by a heap-based buffer over-read in the WriteTIFFImage function in coders/tiff.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause the application to crash.
Other sources
In ImageMagick 7.0.8-36 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, which allows an attacker to cause a denial of service or information disclosure via a crafted image file.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-10650.
What is the severity of CVE-2019-10650?
The severity of CVE-2019-10650 is high with a CVSS score of 8.1.
What is the affected software for CVE-2019-10650?
The affected software for CVE-2019-10650 includes ImageMagick 7.0.8-36 Q16, IBM Data Risk Manager 2.0.6, ImageMagick 6.9.10, and various versions of Ubuntu and Debian.
How can I fix CVE-2019-10650?
To fix CVE-2019-10650, it is recommended to apply the available patches provided by the respective vendors. You can find the patches at the following URL: ImageMagick 7.0.8-36 Q16 - (IBM Data Risk Manager: [link]), ImageMagick 6.9.10 - (Red Hat: [link]), Ubuntu (various versions): [link], Debian (various versions): [link].
Where can I find more information about CVE-2019-10650?
You can find more information about CVE-2019-10650 at the following references: [link], [link], [link].