CVE-2019-13305: Buffer Overflow
ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced strncpy and an off-by-one error.
Other sources
ImageMagick is vulnerable to a denial of service, caused by a stack-based buffer overflow at coders/pnm.c in WritePNMImage. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause the application to crash.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-13305?
CVE-2019-13305 is a vulnerability in ImageMagick 7.0.8-50 Q16 that can be exploited to cause a denial of service.
How severe is CVE-2019-13305?
CVE-2019-13305 has a severity rating of 7.8 out of 10.
Which software versions are affected by CVE-2019-13305?
The affected software versions include IBM Data Risk Manager 2.0.6, ImageMagick 7.0.8-50, and ImageMagick 6.9.10.
How can I fix CVE-2019-13305?
To fix CVE-2019-13305, you can apply the available patches provided by the respective vendors: IBM for Data Risk Manager and Red Hat or Ubuntu for ImageMagick.
Where can I find more information about CVE-2019-13305?
You can refer to the following references for more information about CVE-2019-13305: the OpenSUSE security announcement, the ImageMagick GitHub commit, and the ImageMagick GitHub issue.