CVE-2019-13309: Medium severity ibm data risk manager vulnerability
ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of mishandling the NoSuchImage error in CLIListOperatorImages in MagickWand/operation.c.
Other sources
ImageMagick is vulnerable to a denial of service, caused by memory leaks in the CLIListOperatorImages function in operation.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-13309?
CVE-2019-13309 is a vulnerability in ImageMagick that can cause a denial of service condition due to memory leaks.
Which software versions are affected by CVE-2019-13309?
ImageMagick versions 7.0.8-50 Q16 and 6.9.10 are affected by CVE-2019-13309.
How can an attacker exploit CVE-2019-13309?
An attacker can exploit CVE-2019-13309 by persuading a victim to open a specially-crafted file, triggering the memory leaks and causing a denial of service condition.
What is the severity of CVE-2019-13309?
CVE-2019-13309 has a severity value of 6.5, which is considered medium.
How can I patch or fix CVE-2019-13309?
To fix CVE-2019-13309, patch your ImageMagick software to version 7.0.8-59 or higher.