CVE-2019-15141: Medium severity ibm data risk manager vulnerability
ImageMagick is vulnerable to a denial of service, caused by a heap-based buffer over-read in the WriteTIFFImage in coders/tiff.c. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition.
Other sources
WriteTIFFImage in coders/tiff.c in ImageMagick 7.0.8-43 Q16 allows attackers to cause a denial-of-service (application crash resulting from a heap-based buffer over-read) via a crafted TIFF image file, related to TIFFRewriteDirectory, TIFFWriteDirectory, TIFFWriteDirectorySec, and TIFFWriteDirectoryTagColormap in tifdirwrite.c of LibTIFF. NOTE: this occurs because of an incomplete fix for CVE-2019-11597.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-15141?
CVE-2019-15141 has been classified as a denial of service vulnerability.
How do I fix CVE-2019-15141?
To fix CVE-2019-15141, update to ImageMagick version 7.0.8-43 or later.
What software versions are affected by CVE-2019-15141?
CVE-2019-15141 affects ImageMagick versions 6.9.10 and 7.0.8 up to version 7.0.8-43.
Can CVE-2019-15141 be exploited remotely?
Yes, CVE-2019-15141 can be exploited remotely by sending specially-crafted requests.
What types of systems are impacted by CVE-2019-15141?
CVE-2019-15141 impacts systems running vulnerable versions of ImageMagick on Linux platforms.