CVE-2019-13454: Divide by Zero
ImageMagick 7.0.1-0 to 7.0.8-54 Q16 allows Division by Zero in RemoveDuplicateLayers in MagickCore/layer.c.
Other sources
ImageMagick 7.0.8-54 Q16 allows Division by Zero in RemoveDuplicateLayers in MagickCore/layer.c.
— Launchpad
ImageMagick is vulnerable to a denial of service, caused by a divide by zero flaw in the RemoveDuplicateLayers function in MagickCore/layer.c. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this ImageMagick vulnerability?
The vulnerability ID for this ImageMagick vulnerability is CVE-2019-13454.
What is the severity of CVE-2019-13454?
The severity of CVE-2019-13454 is medium with a CVSS score of 6.5.
Which software versions are affected by CVE-2019-13454?
The affected software versions include IBM Data Risk Manager 2.0.6, ImageMagick 6.9.10 up to version 6.9.10-54, and ImageMagick 7.0.8 up to version 7.0.8-54.
How can I fix CVE-2019-13454 in IBM Data Risk Manager?
To fix CVE-2019-13454 in IBM Data Risk Manager, apply the patch available from IBM Support Fix Central.
Where can I find more information about CVE-2019-13454?
More information about CVE-2019-13454 can be found in the references provided: [Link 1](http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00069.html), [Link 2](http://www.securityfocus.com/bid/109099), [Link 3](https://github.com/ImageMagick/ImageMagick/commit/1ddcf2e4f28029a888cadef2e757509ef5047ad8).