CVE-2019-13310: Medium severity ibm data risk manager vulnerability
ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of an error in MagickWand/mogrify.c.
Other sources
ImageMagick is vulnerable to a denial of service, caused by memory leaks in mogrify.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-13310?
CVE-2019-13310 is a vulnerability in ImageMagick 7.0.8-50 Q16 that causes memory leaks in mogrify.c.
How can this vulnerability be exploited?
This vulnerability can be exploited by persuading a victim to open a specially-crafted file, which would cause a denial of service condition.
What is the severity of CVE-2019-13310?
CVE-2019-13310 has a severity rating of 6.5, which is considered medium.
Which versions of ImageMagick are affected by this vulnerability?
ImageMagick 7.0.8-50 Q16, ImageMagick 6.9.10, and certain versions of ImageMagick on Ubuntu and Debian are affected.
How can I fix CVE-2019-13310?
You can fix CVE-2019-13310 by applying the necessary patches provided by the respective vendors.