Wind River Support Network

HomeDefectsLIN9-8921
Fixed

LIN9-8921 : Security Advisory - imagemagick - CVE-2019-15141

Created: Aug 18, 2019    Updated: Nov 23, 2019
Resolved Date: Nov 23, 2019
Found In Version: 9.0.0.1
Fix Version: 9.0.0.24
Severity: Standard
Applicable for: Wind River Linux 9
Component/s: Userspace

Description

WriteTIFFImage in coders/tiff.c in ImageMagick 7.0.8-43 Q16 allows attackers to cause a denial-of-service (application crash resulting from a heap-based buffer over-read) via a crafted TIFF image file, related to TIFFRewriteDirectory, TIFFWriteDirectory, TIFFWriteDirectorySec, and TIFFWriteDirectoryTagColormap in tif_dirwrite.c of LibTIFF. NOTE: this occurs because of an incomplete fix for CVE-2019-11597.

CREATE(Triage):(User=admin) [CVE-2019-15141|https://nvd.nist.gov/vuln/detail/CVE-2019-15141]

CVEs


Live chat
Online