CVE-2018-7470Improper Restriction of Operations within the Bounds of a Memory Buffer in Imagemagick

Severity
6.5MEDIUMNVD
EPSS
0.2%
top 53.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 25
Latest updateMay 14

Description

An issue was discovered in ImageMagick 7.0.7-22 Q16. The IsWEBPImageLossless function in coders/webp.c allows attackers to cause a denial of service (segmentation violation) via a crafted file.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/imagemagick< imagemagick 8:6.9.9.39+dfsg-1 (bookworm)
Debianimagemagick/imagemagick< 8:6.9.9.39+dfsg-1+3

🔴Vulnerability Details

2
GHSA
GHSA-jvfx-qw69-pwg5: An issue was discovered in ImageMagick 72022-05-14
OSV
CVE-2018-7470: An issue was discovered in ImageMagick 72018-02-25

📋Vendor Advisories

2
Red Hat
ImageMagick: denial of service (DoS) in IsWEBPImageLossless function in coders/webp.c2018-02-23
Debian
CVE-2018-7470: imagemagick - An issue was discovered in ImageMagick 7.0.7-22 Q16. The IsWEBPImageLossless fun...2018

💬Community

2
Bugzilla
CVE-2018-7470 ImageMagick: denial of service (DoS) in IsWEBPImageLossless function in coders/webp.c [fedora-all]2018-02-27
Bugzilla
CVE-2018-7470 ImageMagick: denial of service (DoS) in IsWEBPImageLossless function in coders/webp.c2018-02-27