CVE-2019-13300: Buffer Overflow
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling columns.
Other sources
ImageMagick is vulnerable to a heap-based buffer overflow, caused by improper bounds checking by EvaluateImages in MagickCore/statistic.c. By sending a specially crafted command, a local attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-13300?
CVE-2019-13300 is a vulnerability in ImageMagick 7.0.8-50 Q16 that allows a local attacker to execute arbitrary code or crash the application.
What is the severity of CVE-2019-13300?
The severity of CVE-2019-13300 is high with a CVSS score of 8.8.
Which software is affected by CVE-2019-13300?
ImageMagick 7.0.8-50 Q16, Debian Linux 9.0 and 10.0, Canonical Ubuntu Linux 16.04, 18.04, 19.04, 19.10, openSUSE Leap 15.0 and 15.1.
How can I fix CVE-2019-13300 in Ubuntu?
You can fix CVE-2019-13300 in Ubuntu by updating the 'imagemagick' package to version 8:6.9.10.23+dfsg-2.1ubuntu9 or later.
Where can I find more information about CVE-2019-13300?
You can find more information about CVE-2019-13300 on the CVE Mitre website, Ubuntu Security Notices, and NVD.