CVE-2019-14981: Divide by Zero
ImageMagick is vulnerable to a denial of service, caused by a divide-by-zero vulnerability in the MeanShiftImage function. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause the application to crash.
Other sources
In ImageMagick 7.x before 7.0.8-41 and 6.x before 6.9.10-41, there is a divide-by-zero vulnerability in the MeanShiftImage function. It allows an attacker to cause a denial of service by sending a crafted file.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-14981?
CVE-2019-14981 is a vulnerability in ImageMagick that could allow a remote attacker to cause a denial of service by exploiting a divide-by-zero vulnerability.
What is the severity of CVE-2019-14981?
The severity of CVE-2019-14981 is medium with a CVSS score of 6.5.
How can I fix CVE-2019-14981 in IBM Data Risk Manager?
To fix CVE-2019-14981 in IBM Data Risk Manager, apply the patch available at the provided URL.
How can I fix CVE-2019-14981 in ImageMagick 6.9.10 on Red Hat?
To fix CVE-2019-14981 in ImageMagick 6.9.10 on Red Hat, update to version 6.9.10-41 or later.
How can I fix CVE-2019-14981 in ImageMagick 7.0.8 on Red Hat?
To fix CVE-2019-14981 in ImageMagick 7.0.8 on Red Hat, update to version 7.0.8-41 or later.