In ImageMagick 7.0.8-36 Q16, there is a memory leak in the function SVGKeyValuePairs of coders/svg.c, which allows an attacker to cause a denial of service via a crafted image file.
References
| Link | Resource |
|---|---|
| https://github.com/ImageMagick/ImageMagick/issues/1533 | Exploit Patch Third Party Advisory |
| http://www.securityfocus.com/bid/107645 | Third Party Advisory VDB Entry |
| https://usn.ubuntu.com/4034-1/ | |
| https://www.debian.org/security/2020/dsa-4712 |
Configurations
Information
Published : 2019-03-30 14:29
Updated : 2020-08-24 17:37
NVD link : CVE-2019-10649
Mitre link : CVE-2019-10649
JSON object : View
Products Affected
imagemagick
- imagemagick
CWE
CWE-401
Missing Release of Memory after Effective Lifetime
