4.3
CVSSv2

CVE-2018-16644

Published: 06/09/2018 Updated: 24/08/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

There is a missing check for length in the functions ReadDCMImage of coders/dcm.c and ReadPICTImage of coders/pict.c in ImageMagick 7.0.8-11, which allows remote malicious users to cause a denial of service via a crafted image.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

imagemagick imagemagick 7.0.8-11

debian debian linux 9.0

debian debian linux 8.0

canonical ubuntu linux 18.04

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

Vendor Advisories

Several security issues were fixed in ImageMagick ...
Several security issues were fixed in ImageMagick ...
Debian Bug report logs - #910888 imagemagick: CVE-2018-16644 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 12 Oct 2018 19:24:01 UTC Severity: grave Tags: fixed-upstr ...
Debian Bug report logs - #907776 imagemagick: CVE-2018-16323 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 1 Sep 2018 20:24:02 UTC Severity: important Tags: patch, ...
Debian Bug report logs - #910887 imagemagick: CVE-2018-16412 CVE-2018-16413 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 12 Oct 2018 19:18:02 UTC Severity: grave Ta ...
Debian Bug report logs - #910889 imagemagick: CVE-2018-16645 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 12 Oct 2018 19:27:01 UTC Severity: grave Tags: fixed-upstr ...
There is a missing check for length in the functions ReadDCMImage of coders/dcmc and ReadPICTImage of coders/pictc in ImageMagick 708-11, which allows remote attackers to cause a denial of service via a crafted image ...