CVE-2019-12978: High severity ibm data risk manager vulnerability
A vulnerability was found in ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the ReadPANGOImage function in coders/pango.c.
Reference: https://github.com/ImageMagick/ImageMagick/issues/1519
Other sources
ImageMagick is vulnerable to a denial of service, caused by the use of uninitialized value vulnerability in the ReadPANGOImage function in coders/pango.c. By persuading a victim to open a specially crafted file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-12978?
CVE-2019-12978 is a vulnerability in ImageMagick that allows an attacker to cause a denial of service by exploiting an uninitialized value vulnerability in the ReadPANGOImage function.
How can the CVE-2019-12978 vulnerability be exploited?
CVE-2019-12978 vulnerability can be exploited by convincing a user to open a specially crafted file.
What is the severity of CVE-2019-12978?
CVE-2019-12978 has a severity rating of 7.8, which is considered high.
Which software versions are affected by CVE-2019-12978?
CVE-2019-12978 affects ImageMagick versions 7.0.8-34.
How can I fix CVE-2019-12978?
To fix CVE-2019-12978, update to the latest version of ImageMagick that includes the security patch.