CVE-2019-11470: High severity ibm data risk manager vulnerability
ImageMagick is vulnerable to a denial of service, caused by uncontrolled resource consumption in the ReadXWDImage function in coders/xwd.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause the application to crash.
Other sources
The cineon parsing component in ImageMagick 7.0.8-26 Q16 allows attackers to cause a denial-of-service (uncontrolled resource consumption) by crafting a Cineon image with an incorrect claimed image size. This occurs because ReadCINImage in coders/cin.c lacks a check for insufficient image data in a file.
Reference: https://github.com/ImageMagick/ImageMagick/issues/1472
Upstream commit: https://github.com/ImageMagick/ImageMagick/commit/e3cdce6fe12193f235b8c0ae5efe6880a25eb957
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-11470?
CVE-2019-11470 is a vulnerability in ImageMagick that allows attackers to cause a denial-of-service by crafting a Cineon image with an incorrect claimed image size.
How severe is CVE-2019-11470?
CVE-2019-11470 has a severity rating of 6.5, which is considered high.
Which software versions are affected by CVE-2019-11470?
IBM Data Risk Manager version 2.0.6, ImageMagick 6.9.10, and ImageMagick 7.0.8 are affected by CVE-2019-11470.
How can I fix CVE-2019-11470 in IBM Data Risk Manager?
You can fix CVE-2019-11470 in IBM Data Risk Manager by applying the patch available in the IBM Support Fix Central website.
Is there a patch available for CVE-2019-11470 in ImageMagick?
Yes, there are patches available for CVE-2019-11470 in the affected versions of ImageMagick. Please refer to the respective vendor's website for more information.