CVE-2019-17541: Use After Free
ImageMagick before 7.0.8-55 has a use-after-free in DestroyStringInfo in MagickCore/string.c because the error manager is mishandled in coders/jpeg.c.
Other sources
ImageMagick could allow a remote attacker to execute arbitrary code on the system, caused by a heap use-after-free in the DestroyStringInfo function in MagickCore/string.c. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-17541?
CVE-2019-17541 has a high severity rating due to its potential to allow remote code execution.
How do I fix CVE-2019-17541?
To fix CVE-2019-17541, update ImageMagick to version 6.9.10-55 or later, or version 7.0.8-55 or later.
Who is affected by CVE-2019-17541?
CVE-2019-17541 affects all versions of ImageMagick prior to 6.9.10-55 and versions from 7.0.0-0 up to 7.0.8-55.
What type of attack can exploit CVE-2019-17541?
An attacker can exploit CVE-2019-17541 by persuading a victim to open a specially-crafted image file.
Is CVE-2019-17541 a critical vulnerability?
Yes, CVE-2019-17541 is classified as a critical vulnerability due to its ability to execute arbitrary code on the affected system.