CVE-2019-16709: Medium severity ibm data risk manager vulnerability
A vulnerability was found in ImageMagick 7.0.8-35 has a memory leak in coders/dps.c, as demonstrated by XCreateImage.
Reference: https://github.com/ImageMagick/ImageMagick/issues/1531
Other sources
ImageMagick is vulnerable to a denial of service, caused by a memory leak in coders/dps.c. By persuading a victim to open a specially crafted file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-16709?
CVE-2019-16709 is a vulnerability in ImageMagick 7.0.8-35 that causes a memory leak in coders/dps.c.
How does CVE-2019-16709 affect ImageMagick?
CVE-2019-16709 can be exploited by opening a specially crafted file, potentially leading to a denial of service attack.
What is the severity rating of CVE-2019-16709?
CVE-2019-16709 has a severity rating of 6.5 (medium).
What software versions are affected by CVE-2019-16709?
Versions 7.0.8-35 of ImageMagick, 2.0.6 of IBM Data Risk Manager, and certain versions of openSUSE Leap and Ubuntu Linux are affected.
How do I fix CVE-2019-16709?
To fix CVE-2019-16709, apply the patches provided by the respective vendors or upgrade to the specified versions.