CVE-2018-18544Missing Release of Resource after Effective Lifetime in Graphicsmagick

Severity
6.5MEDIUMNVD
EPSS
0.2%
top 64.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 21
Latest updateMay 13

Description

There is a memory leak in the function WriteMSLImage of coders/msl.c in ImageMagick 7.0.8-13 Q16, and the function ProcessMSLScript of coders/msl.c in GraphicsMagick before 1.3.31.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages7 packages

debiandebian/imagemagick< graphicsmagick 1.3.31-1 (bookworm)
debiandebian/graphicsmagick< graphicsmagick 1.3.31-1 (bookworm)
Debianimagemagick/imagemagick< 8:6.9.10.14+dfsg-1+3
Debiangraphicsmagick/graphicsmagick< 1.3.31-1+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-w2cq-hjvv-8q4h: There is a memory leak in the function WriteMSLImage of coders/msl2022-05-13
OSV
CVE-2018-18544: There is a memory leak in the function WriteMSLImage of coders/msl2018-10-21

📋Vendor Advisories

3
Ubuntu
ImageMagick vulnerabilities2019-06-25
Red Hat
ImageMagick: memory leak in WriteMSLImage of coders/msl.c2018-10-19
Debian
CVE-2018-18544: graphicsmagick - There is a memory leak in the function WriteMSLImage of coders/msl.c in ImageMag...2018

💬Community

2
Bugzilla
CVE-2018-18544 ImageMagick: memory leak in WriteMSLImage of coders/msl.c [fedora-all]2018-10-24
Bugzilla
CVE-2018-18544 ImageMagick: memory leak in WriteMSLImage of coders/msl.c2018-10-24