CVE-2019-7397: High severity ibm data risk manager vulnerability
ImageMagick is vulnerable to a denial of service, caused by memory leaks in WritePDFImage in coders/pdf.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause the application to crash.
Other sources
In ImageMagick before 7.0.8-25 and GraphicsMagick through 1.3.31, several memory leaks exist in WritePDFImage in coders/pdf.c.
— Launchpad
In ImageMagick before 7.0.8-25, several memory leaks exist in WritePDFImage in coders/pdf.c.
References: https://github.com/ImageMagick/ImageMagick/commit/306c1f0fa5754ca78efd16ab752f0e981d4f6b82 https://github.com/ImageMagick/ImageMagick/issues/1454
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-7397.
What is the title of this vulnerability?
The title of this vulnerability is 'In ImageMagick before 7.0.8-25 and GraphicsMagick through 1.3.31 several memory leaks exist in Write...'.
What is the severity of CVE-2019-7397?
The severity of CVE-2019-7397 is high with a CVSS score of 7.5.
What versions of ImageMagick and GraphicsMagick are affected by this vulnerability?
ImageMagick versions 6.9.10-25 and 7.0.8-25, as well as GraphicsMagick version 1.3.31 are affected by this vulnerability.
How can I fix CVE-2019-7397?
To fix CVE-2019-7397, you should apply the available patches provided by the respective vendors: IBM for Data Risk Manager, Red Hat for ImageMagick, and Debian for GraphicsMagick.