CVE-2018-16413
Published: 03 September 2018
ImageMagick 7.0.8-11 Q16 has a heap-based buffer over-read in the MagickCore/quantum-private.h PushShortPixel function when called from the coders/psd.c ParseImageResourceBlocks function.
Priority
CVSS 3 base score: 8.8
Status
Package | Release | Status |
---|---|---|
imagemagick Launchpad, Ubuntu, Debian |
Upstream |
Released
(6.9.10-11)
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Released
(8:6.9.7.4+dfsg-16ubuntu6.7)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Released
(8:6.8.9.9-7ubuntu5.14)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
(trusty was needed)
|
|
Patches: Upstream: https://github.com/ImageMagick/ImageMagick6/commit/4745eb1047617330141e9abfd5ae01236a71ae12 Upstream: https://github.com/ImageMagick/ImageMagick/commit/17a1a6f97fd088a71931bdc422f4e96bb6ffc549 |
Notes
Author | Note |
---|---|
sbeattie | PoC in github issue |
mdeslaur | same patch as CVE-2018-16412 |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16413
- https://usn.ubuntu.com/usn/usn-4034-1
- NVD
- Launchpad
- Debian