CVE-2019-13307: Buffer Overflow
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling rows.
Other sources
ImageMagick is vulnerable to a denial of service, caused by a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause the application to crash.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-13307?
CVE-2019-13307 is a vulnerability in ImageMagick 7.0.8-50 Q16 that allows a remote attacker to cause a denial of service.
How does CVE-2019-13307 work?
CVE-2019-13307 is caused by a heap-based buffer overflow in EvaluateImages in the MagickCore/statistic.c file of ImageMagick, which can be exploited by persuading a victim to open a specially-crafted file.
What is the severity of CVE-2019-13307?
CVE-2019-13307 has a severity value of 7.8 (high).
Is there a patch available for CVE-2019-13307?
Yes, a patch is available to fix CVE-2019-13307. You can find the patch for IBM Data Risk Manager at [this link](https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=IBM%20Security&product=ibm/Other+software/IBM+Data+Risk+Manager&release=2.0.4.1&platform=Linux&function=all).
What versions of ImageMagick are affected by CVE-2019-13307?
ImageMagick 7.0.8-50 Q16, ImageMagick 6.9.10, and various versions of ImageMagick in Ubuntu, Debian, and openSUSE are affected by CVE-2019-13307.