CVE-2018-18024 PUBLISHED

In ImageMagick 7.0.8-13 Q16, there is an infinite loop in the ReadBMPImage function of the coders/bmp.c file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.

EPSS 0.32% · 54.9th percentile

Risk Scores

EPSS Score
0.32%
54.9th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSimagemagick0, 8:6.8.9.9-5ubuntu2, 8:6.8.9.9-6
Ubuntu:Pro:14.04:LTSimagemagick8:6.7.7.10-6ubuntu3.13+esm5, 8:6.7.7.10-6ubuntu3.13+esm6, 8:6.7.7.10-6ubuntu3.13+esm7
Ubuntu:18.04:LTSimagemagick0, 8:6.9.7.4+dfsg-16ubuntu2, 8:6.9.7.4+dfsg-16ubuntu3

Timeline

References

Open in Interactive Console →