CVE-2019-7175: High severity ibm data risk manager vulnerability
ImageMagick could allow a remote attacker to obtain sensitive information, caused by memory leaks in DecodeImage in coders/pcd.c. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to obtain sensitive information.
Other sources
In ImageMagick before 7.0.8-25, some memory leaks exist in DecodeImage in coders/pcd.c.
Reference: https://github.com/ImageMagick/ImageMagick/issues/1450
Upstream commit: https://github.com/ImageMagick/ImageMagick/commit/1e6a3ace073c9ec9c71e439c111d23c6e66cb6ae
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7175?
The severity of CVE-2019-7175 is high with a severity value of 7.5.
How does CVE-2019-7175 affect ImageMagick?
CVE-2019-7175 affects ImageMagick by causing memory leaks in the DecodeImage function in coders/pcd.c.
How can a remote attacker exploit CVE-2019-7175?
A remote attacker can exploit CVE-2019-7175 by persuading a victim to open a specially-crafted file, allowing the attacker to obtain sensitive information.
Which versions of ImageMagick are affected by CVE-2019-7175?
Versions of ImageMagick up to and including 7.0.8-25 are affected by CVE-2019-7175.
Is there a patch or update available for CVE-2019-7175?
Yes, there are patches and updates available for CVE-2019-7175. Please check the references for more information.