CVE-2019-15140: Use After Free
coders/mat.c in ImageMagick 7.0.8-43 Q16 allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact by crafting a Matlab image file that is mishandled in ReadImage in MagickCore/constitute.c.
Other sources
ImageMagick is vulnerable to a denial of service, caused by a use-after-free in the coders/mat.c. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-15140?
CVE-2019-15140 is a vulnerability in ImageMagick 7.0.8-43 that allows remote attackers to cause a denial of service or possibly have other impact by crafting a Matlab image file.
What is the severity of CVE-2019-15140?
The severity of CVE-2019-15140 is high with a CVSS score of 8.8.
How do I know if I am affected by CVE-2019-15140?
You are affected by CVE-2019-15140 if you are using ImageMagick version 7.0.8-43 Q16.
How can I fix CVE-2019-15140?
To fix CVE-2019-15140, apply the patch provided by ImageMagick or upgrade to a version that is not affected.
Where can I find more information about CVE-2019-15140?
You can find more information about CVE-2019-15140 on the CVE Mitre website, Ubuntu Security Notices, and the NIST NVD website.