CVE-2019-16708: Medium severity ibm data risk manager vulnerability
A vulnerability was found in ImageMagick 7.0.8-35 has a memory leak in magick/xwindow.c, related to XCreateImage.
Reference: https://github.com/ImageMagick/ImageMagick/issues/1531
Other sources
ImageMagick is vulnerable to a denial of service, caused by a memory leak in magick/xwindow.c. By persuading a victim to open a specially crafted file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-16708?
CVE-2019-16708 is a vulnerability in ImageMagick 7.0.8-35 that can be exploited to cause a denial of service condition due to a memory leak in magick/xwindow.c.
How severe is CVE-2019-16708?
CVE-2019-16708 has a severity rating of 6.5, which is considered medium.
Which software versions are affected by CVE-2019-16708?
ImageMagick versions 7.0.8-35, 6.9.10, 6.9.11, and 6.9.12 are affected by CVE-2019-16708.
How can CVE-2019-16708 be fixed?
To fix CVE-2019-16708, users should update to the patched versions of ImageMagick provided by the vendor.
Where can I find more information about CVE-2019-16708?
You can find more information about CVE-2019-16708 on the following references: [1] [2] [3]