SB2019050312 - Division by zero in imagemagick6 (Alpine package)
Published: May 3, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Division by zero (CVE-ID: CVE-2019-11472)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
ReadXWDImage in coders/xwd.c in the XWD image parsing component of ImageMagick 7.0.8-41 Q16 allows attackers to cause a denial-of-service (divide-by-zero error) by crafting an XWD image file in which the header indicates neither LSB first nor MSB first.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=209132f82cd396cf5db8b9922af19ac2993d5fd7
- https://git.alpinelinux.org/aports/commit/?id=e5c3f995a8c86f93b1be124877faacac90c55929
- https://git.alpinelinux.org/aports/commit/?id=0f7ecd696d28f3be16555aca8525bf57ed8a0669
- https://git.alpinelinux.org/aports/commit/?id=29e36876490fbbf485171dfdfa0a8cdde53f0202
- https://git.alpinelinux.org/aports/commit/?id=30218e0b6e027c2b51d4088f0b975e8f134d0e36
- https://git.alpinelinux.org/aports/commit/?id=0bb735b52e70a294b35c638b3334bf54740cbd67
- https://git.alpinelinux.org/aports/commit/?id=b86c9d69ef22f66add28b947c238717d4e78c015
- https://git.alpinelinux.org/aports/commit/?id=baeaae173050e00e11e98128097f48855500e1a7
- https://git.alpinelinux.org/aports/commit/?id=dad39c70aeb47d2083d865a24c1a015c3aea3be4