SB2019050315 - Out-of-bounds read in imagemagick6 (Alpine package)
Published: May 3, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2019-11597)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, which allows an attacker to cause a denial of service or possibly information disclosure via a crafted image file. A remote attacker can perform a denial of service attack.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=530a544685f085941dfc43575144a1aa5090a3e4
- https://git.alpinelinux.org/aports/commit/?id=6a183d66c7dc3dca62a642c621c62bc6455f8b87
- https://git.alpinelinux.org/aports/commit/?id=e2c99a977c70ec025f2ce7b2e89c227d7fed9ed7
- https://git.alpinelinux.org/aports/commit/?id=0f7ecd696d28f3be16555aca8525bf57ed8a0669
- https://git.alpinelinux.org/aports/commit/?id=29e36876490fbbf485171dfdfa0a8cdde53f0202
- https://git.alpinelinux.org/aports/commit/?id=30218e0b6e027c2b51d4088f0b975e8f134d0e36
- https://git.alpinelinux.org/aports/commit/?id=0bb735b52e70a294b35c638b3334bf54740cbd67
- https://git.alpinelinux.org/aports/commit/?id=b86c9d69ef22f66add28b947c238717d4e78c015
- https://git.alpinelinux.org/aports/commit/?id=baeaae173050e00e11e98128097f48855500e1a7
- https://git.alpinelinux.org/aports/commit/?id=dad39c70aeb47d2083d865a24c1a015c3aea3be4