CVE-2018-6405 PUBLISHED

In the ReadDCMImage function in coders/dcm.c in ImageMagick before 7.0.7-23, each redmap, greenmap, and bluemap variable can be overwritten by a new pointer. The previous pointer is lost, which leads to a memory leak. This allows remote attackers to cause a denial of service.

EPSS 0.99% · 76.7th percentile

Risk Scores

EPSS Score
0.99%
76.7th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSimagemagick8:6.9.7.4+dfsg-16ubuntu6, 8:6.9.7.4+dfsg-16ubuntu5, 8:6.9.7.4+dfsg-16ubuntu4
Ubuntu:14.04:LTSimagemagick8:6.7.7.10-6ubuntu3.1, 8:6.7.7.10-6ubuntu3.2, 8:6.7.7.10-6ubuntu3.3
Ubuntu:16.04:LTSimagemagick8:6.8.9.9-7ubuntu2, 8:6.8.9.9-7ubuntu3, 8:6.8.9.9-7ubuntu4

Timeline

References

Open in Interactive Console →