CVE-2019-15139: Medium severity ibm data risk manager vulnerability
ImageMagick is vulnerable to a denial of service, caused by an out-of-bounds read in ReadXWDImage in coders/xwd.c. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition.
Other sources
The XWD image (X Window System window dumping file) parsing component in ImageMagick 7.0.8-41 Q16 allows attackers to cause a denial-of-service (application crash resulting from an out-of-bounds Read) in ReadXWDImage in coders/xwd.c by crafting a corrupted XWD image file, a different vulnerability than CVE-2019-11472.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-15139?
CVE-2019-15139 is a vulnerability in ImageMagick that allows attackers to cause a denial-of-service by crafting a corrupted XWD image file.
How severe is CVE-2019-15139?
CVE-2019-15139 has a severity rating of 6.5 out of 10.
Which software versions are affected by CVE-2019-15139?
ImageMagick 7.0.8-41 Q16 and IBM Data Risk Manager 2.0.6 are affected by CVE-2019-15139.
How can I fix CVE-2019-15139 in ImageMagick?
You can fix CVE-2019-15139 in ImageMagick by applying the patch provided by the vendor.
Where can I find more information about CVE-2019-15139?
You can find more information about CVE-2019-15139 at the following references: [link1], [link2], [link3].