cbcvebase.
CVE-2019-15141
published 2019-08-18

CVE-2019-15141: WriteTIFFImage in coders/tiff.c in ImageMagick 7.0.8-43 Q16 allows attackers to cause a denial-of-service (application crash resulting from a heap-based buffer…

PriorityP425medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
2.18%
80.5th percentile
WriteTIFFImage in coders/tiff.c in ImageMagick 7.0.8-43 Q16 allows attackers to cause a denial-of-service (application crash resulting from a heap-based buffer over-read) via a crafted TIFF image file, related to TIFFRewriteDirectory, TIFFWriteDirectory, TIFFWriteDirectorySec, and TIFFWriteDirectoryTagColormap in tif_dirwrite.c of LibTIFF. NOTE: this occurs because of an incomplete fix for CVE-2019-11597.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianimagemagick
imagemagickimagemagick
imagemagickimagemagick>= 0 < 8:6.8.9.9-7ubuntu5.148:6.8.9.9-7ubuntu5.14
imagemagickimagemagick>= 0 < 8:6.9.7.4+dfsg-16ubuntu6.78:6.9.7.4+dfsg-16ubuntu6.7
imagemagickimagemagick>= 0 < 8:6.7.7.10-6ubuntu3.13+esm108:6.7.7.10-6ubuntu3.13+esm10
opensuseleap
opensuseleap

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv8.1HIGH
vendor_debian8.1LOW
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.