The vendor explicitly identifies these products as affected by this CVE.
- ImageMagick as a component of Red Hat Enterprise Linux 6
- ImageMagick-c++ as a component of Red Hat Enterprise Linux 6
- ImageMagick-c++-devel as a component of Red Hat Enterprise Linux 6
- ImageMagick-devel as a component of Red Hat Enterprise Linux 6
- ImageMagick-doc as a component of Red Hat Enterprise Linux 6
- ImageMagick-perl as a component of Red Hat Enterprise Linux 6
- ImageMagick.src as a component of Red Hat Enterprise Linux 6
- ImageMagick as a component of Red Hat Enterprise Linux 7
- ImageMagick-c++ as a component of Red Hat Enterprise Linux 7
- ImageMagick-c++-devel as a component of Red Hat Enterprise Linux 7
- ImageMagick-devel as a component of Red Hat Enterprise Linux 7
- ImageMagick-doc as a component of Red Hat Enterprise Linux 7
- Summary
- A flaw was found in ImageMagick, a free and open-source software used for editing and manipulating digital images. A local attacker could exploit this vulnerability by providing an extremely large image profile when encoding a PNG image. This could result in a heap overflow, leading to a Denial of Service (DoS), which makes the affected system or application unavailable to legitimate users.
- Remediation
- To mitigate this issue, avoid processing untrusted or maliciously crafted image files with ImageMagick. Users should exercise caution when handling image files from unknown or suspicious sources.
