CVE-2019-12975: Medium severity ibm data risk manager vulnerability
ImageMagick 7.0.8-34 has a memory leak vulnerability in the WriteDPXImage function in coders/dpx.c.
Reference: https://github.com/ImageMagick/ImageMagick/issues/1517
Other sources
ImageMagick is vulnerable to a denial of service, caused by a memory leak in the WriteDPXImage function in coders/dpx.c. By persuading a victim to open a specially crafted file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-12975?
CVE-2019-12975 is a memory leak vulnerability in the WriteDPXImage function in coders/dpx.c in ImageMagick 7.0.8-34.
How severe is CVE-2019-12975?
CVE-2019-12975 has a severity value of 5.5, which is considered medium.
How can CVE-2019-12975 be exploited?
CVE-2019-12975 can be exploited by persuading a victim to open a specially crafted file, which can cause a denial of service condition.
What is the affected software?
The affected software includes ImageMagick 7.0.8-34 and various versions in different distributions.
How can I fix CVE-2019-12975?
To fix CVE-2019-12975, update to the recommended versions provided by the respective distributions or apply the available patches.