[Pkg-gmagick-im-team] Bug#927830: imagemagick: CVE-2019-11470

Salvatore Bonaccorso carnil at debian.org
Tue Apr 23 21:53:05 BST 2019


Source: imagemagick
Version: 8:6.9.10.23+dfsg-2
Severity: important
Tags: security upstream
Forwarded: https://github.com/ImageMagick/ImageMagick/issues/1472

Hi,

The following vulnerability was published for imagemagick.

CVE-2019-11470[0]:
| The cineon parsing component in ImageMagick 7.0.8-26 Q16 allows
| attackers to cause a denial-of-service (uncontrolled resource
| consumption) by crafting a Cineon image with an incorrect claimed
| image size. This occurs because ReadCINImage in coders/cin.c lacks a
| check for insufficient image data in a file.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2019-11470
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11470
[1] https://github.com/ImageMagick/ImageMagick/issues/1472
[2] https://github.com/ImageMagick/ImageMagick6/commit/a0473b29add9521ffd4c74f6f623b418811762b0

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



More information about the Pkg-gmagick-im-team mailing list