CVE-2019-16712: Medium severity ibm data risk manager vulnerability
A vulnerability was found in ImageMagick 7.0.8-43 has a memory leak in Huffman2DEncodeImage in coders/ps3.c, as demonstrated by WritePS3Image.
Reference: https://github.com/ImageMagick/ImageMagick/issues/1557
Other sources
ImageMagick is vulnerable to a denial of service, caused by a memory leak in Huffman2DEncodeImage in coders/ps3.c. By persuading a victim to open a specially crafted file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-16712?
CVE-2019-16712 has been classified with a medium severity due to its memory leak affecting ImageMagick.
How do I fix CVE-2019-16712?
To mitigate CVE-2019-16712, upgrade ImageMagick to version 7.0.8-44 or later.
Which versions of ImageMagick are affected by CVE-2019-16712?
CVE-2019-16712 affects ImageMagick versions up to and including 7.0.8-43.
Is there a specific product related to CVE-2019-16712?
Yes, CVE-2019-16712 specifically impacts ImageMagick, a widely used image processing software.
Can CVE-2019-16712 lead to other security issues?
Yes, memory leaks like those in CVE-2019-16712 can potentially lead to performance degradation or stability issues in applications using the affected software.