SB2019050422 - Resource management error in imagemagick6 (Alpine package)
Published: May 4, 2019
Security Bulletin ID
SB2019050422
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2019-13309)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists because of a memory leak in AcquireMagickMemory due to mishandling the NoSuchImage error in CLIListOperatorImages in the "MagickWand/operation.c" file. A remote attacker can perform a denial of service attack.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=a19f810872972ce57a3fd3bf4ef1f9ec5eac78bc
- https://git.alpinelinux.org/aports/commit/?id=530a544685f085941dfc43575144a1aa5090a3e4
- https://git.alpinelinux.org/aports/commit/?id=d46d1b3369612e10a726fb1b6658764a7ff08fc9
- https://git.alpinelinux.org/aports/commit/?id=6a183d66c7dc3dca62a642c621c62bc6455f8b87
- https://git.alpinelinux.org/aports/commit/?id=8a0a53d2ab69a2e8892826f9443e0ad20d53e4df
- https://git.alpinelinux.org/aports/commit/?id=3cecfd2d2af53b9be6d7e3af4cc8490b54556a1f
- https://git.alpinelinux.org/aports/commit/?id=4f797cc6b00076db68e8bc9f0995e8181659d243
- https://git.alpinelinux.org/aports/commit/?id=e2c99a977c70ec025f2ce7b2e89c227d7fed9ed7
- https://git.alpinelinux.org/aports/commit/?id=0f7ecd696d28f3be16555aca8525bf57ed8a0669