CVE-2019-7398: High severity ibm data risk manager vulnerability
ImageMagick is vulnerable to a denial of service, caused by a memory leak in WriteDIBImage in coders/dib.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause the application to crash.
Other sources
In ImageMagick before 7.0.8-25, a memory leak exists in WriteDIBImage in coders/dib.c.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-7398?
CVE-2019-7398 is a vulnerability in ImageMagick that allows a remote attacker to cause a denial of service by exploiting a memory leak in WriteDIBImage in coders/dib.c.
How severe is CVE-2019-7398?
CVE-2019-7398 has a severity rating of high with a CVSS score of 7.5.
Which versions of ImageMagick are affected by CVE-2019-7398?
CVE-2019-7398 affects ImageMagick versions up to 8:6.9.10.23+dfsg-2.1ubuntu2.
How can I fix CVE-2019-7398?
To fix CVE-2019-7398, apply the appropriate patch or update provided by the vendor or package maintainer.
Where can I find more information about CVE-2019-7398?
You can find more information about CVE-2019-7398 on the OpenSUSE Security Announce mailing list and the SecurityFocus website.