CVE-2019-11597: High severity ibm data risk manager vulnerability
ImageMagick is vulnerable to a denial of service, caused by a heap-based buffer over-read in the WritePNMImage function in coders/pnm.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause a denial of service or possibly obtain sensitive information.
Other sources
In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, which allows an attacker to cause a denial of service or possibly information disclosure via a crafted image file.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2019-11597.
What is the severity of CVE-2019-11597?
The severity of CVE-2019-11597 is high with a CVSS score of 8.1.
Which software versions are affected by CVE-2019-11597?
The affected software versions include ImageMagick 7.0.8-43 Q16.
How can I fix CVE-2019-11597?
To fix CVE-2019-11597, update ImageMagick to version 8:6.9.7.4+dfsg-16ubuntu6.7 or later.
Where can I find more information about CVE-2019-11597?
You can find more information about CVE-2019-11597 on the following references: [SecurityFocus](http://www.securityfocus.com/bid/108102), [GitHub](https://github.com/ImageMagick/ImageMagick/issues/1555), [Debian LTS](https://lists.debian.org/debian-lts-announce/2019/05/msg00015.html).