CVE-2019-13301: Medium severity ibm data risk manager vulnerability
ImageMagick 7.0.8-50 Q16 has memory leaks in AcquireMagickMemory because of an AnnotateImage error.
Other sources
ImageMagick is vulnerable to a denial of service, caused by memory leaks in AcquireMagickMemory due to AnnotateImage error. By sending a specially crafted command, a local attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-13301?
CVE-2019-13301 is a vulnerability in ImageMagick 7.0.8-50 Q16 that can be exploited to cause a denial of service.
How severe is CVE-2019-13301?
CVE-2019-13301 has a severity rating of 6.5, which is considered medium.
Which software versions are affected by CVE-2019-13301?
ImageMagick 7.0.8-50 Q16, Debian Linux 10.0, and various versions of Ubuntu and openSUSE Leap are affected by CVE-2019-13301.
How can I fix CVE-2019-13301?
Apply the latest patches or updates provided by the software vendor, such as the patch from IBM for Data Risk Manager.