CVE-2023-5349
published 2023-10-30CVE-2023-5349: A memory leak flaw was found in ruby-magick, an interface between Ruby and ImageMagick. This issue can lead to a denial of service (DOS) by memory exhaustion.
PriorityP48low3.3CVSS 3.1
AVLACLPRNUIRSUCNINAL
EPSS
0.67%
47.8th percentile
A memory leak flaw was found in ruby-magick, an interface between Ruby and ImageMagick. This issue can lead to a denial of service (DOS) by memory exhaustion.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ruby-rmagick | < ruby-rmagick 2.16.0-7+deb11u1 (bullseye) | ruby-rmagick 2.16.0-7+deb11u1 (bullseye) |
| fedoraproject | fedora | — | — |
| rmagick | rmagick | < 5.3.0 | 5.3.0 |
| rmagick | rmagick | >= 0 < 5.3.0 | 5.3.0 |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
osv3.3LOW
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
RMagick vulnerability
vendor_ubuntu·2024-08-14
CVE-2023-5349 RMagick vulnerability
Title: RMagick vulnerability
Summary: RMagick could be made to crash if it received specially crafted input.
Nick Browning discovered that RMagick incorrectly handled memory under
certain operations. An attacker could possibly use this issue to cause
a denial of service through memory exhaustion.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
rubygem-rmagick: Memory leak by Magick::Draw while calling GetDrawInfo()
vendor_redhat·2023-07-07·CVSS 5.3
CVE-2023-5349 [MEDIUM] CWE-401 rubygem-rmagick: Memory leak by Magick::Draw while calling GetDrawInfo()
rubygem-rmagick: Memory leak by Magick::Draw while calling GetDrawInfo()
A memory leak flaw was found in ruby-magick, an interface between Ruby and ImageMagick. This issue can lead to a denial of service (DOS) by memory exhaustion.
A memory leak flaw was found in ruby-magick, an interface between Ruby and ImageMagick. This issue can lead to a denial of service (DOS) by memory exhaustion.
Package: 3scale-amp-system-container (Red Hat 3scale API Management Platform 2) - Not affected
Debian
CVE-2023-5349: ruby-rmagick - A memory leak flaw was found in ruby-magick, an interface between Ruby and Image...
vendor_debian·2023·CVSS 5.3
CVE-2023-5349 [MEDIUM] CVE-2023-5349: ruby-rmagick - A memory leak flaw was found in ruby-magick, an interface between Ruby and Image...
A memory leak flaw was found in ruby-magick, an interface between Ruby and ImageMagick. This issue can lead to a denial of service (DOS) by memory exhaustion.
Scope: local
bookworm: open
bullseye: resolved (fixed in 2.16.0-7+deb11u1)
forky: resolved (fixed in 5.3.0-1)
sid: resolved (fixed in 5.3.0-1)
trixie: resolved (fixed in 5.3.0-1)
GHSA
memory leak flaw was found in ruby-magick
ghsa·2023-10-30
CVE-2023-5349 [MEDIUM] CWE-400 memory leak flaw was found in ruby-magick
memory leak flaw was found in ruby-magick
A memory leak flaw was found in ruby-magick, an interface between Ruby and ImageMagick. This issue can lead to a denial of service (DOS) by memory exhaustion.
OSV
CVE-2023-5349: A memory leak flaw was found in ruby-magick, an interface between Ruby and ImageMagick
osv·2023-10-30·CVSS 3.3
CVE-2023-5349 [LOW] CVE-2023-5349: A memory leak flaw was found in ruby-magick, an interface between Ruby and ImageMagick
A memory leak flaw was found in ruby-magick, an interface between Ruby and ImageMagick. This issue can lead to a denial of service (DOS) by memory exhaustion.
OSV
memory leak flaw was found in ruby-magick
osv·2023-10-30
CVE-2023-5349 [MEDIUM] memory leak flaw was found in ruby-magick
memory leak flaw was found in ruby-magick
A memory leak flaw was found in ruby-magick, an interface between Ruby and ImageMagick. This issue can lead to a denial of service (DOS) by memory exhaustion.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2023-5349https://bugzilla.redhat.com/show_bug.cgi?id=2247064https://github.com/rmagick/rmagick/issues/1401https://github.com/rmagick/rmagick/pull/1406https://lists.fedoraproject.org/archives/list/[email protected]/message/S3XMQ2KWPYGT447EKPENGXXHKAQ5NUWF/https://access.redhat.com/security/cve/CVE-2023-5349https://bugzilla.redhat.com/show_bug.cgi?id=2247064https://github.com/rmagick/rmagick/issues/1401https://github.com/rmagick/rmagick/pull/1406https://lists.debian.org/debian-lts-announce/2023/10/msg00030.htmlhttps://lists.debian.org/debian-lts-announce/2026/01/msg00003.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/S3XMQ2KWPYGT447EKPENGXXHKAQ5NUWF/
2023-10-30
Published