CVE-2019-11598: High severity ibm data risk manager vulnerability
ImageMagick is vulnerable to a denial of service, caused by a heap-based buffer over-read in the WritePNMImage function in coders/pnm.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause a denial of service or possibly obtain sensitive information.
Other sources
In ImageMagick 7.0.8-40 Q16, there is a heap-based buffer over-read in the function WritePNMImage of coders/pnm.c, which allows an attacker to cause a denial of service or possibly information disclosure via a crafted image file.
Upstream issue: https://github.com/ImageMagick/ImageMagick/issues/1540
— Red Hat
In ImageMagick 7.0.8-40 Q16, there is a heap-based buffer over-read in the function WritePNMImage of coders/pnm.c, which allows an attacker to cause a denial of service or possibly information disclosure via a crafted image file. This is related to SetGrayscaleImage in MagickCore/quantize.c.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-11598.
What is the severity of CVE-2019-11598?
The severity of CVE-2019-11598 is high.
How does the vulnerability in ImageMagick affect the software?
The vulnerability in ImageMagick can cause a denial of service or possibly obtain sensitive information.
Which versions of ImageMagick are affected by CVE-2019-11598?
Versions 7.0.8-40 Q16 of ImageMagick are affected by CVE-2019-11598.
Where can I find more information about CVE-2019-11598?
You can find more information about CVE-2019-11598 at the following references: [link1](http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00057.html), [link2](http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00001.html), [link3](http://www.securityfocus.com/bid/108102).