CVE-2019-17541
ImageMagick: Use after free in ReadICCProfile function in coders/jpeg.c
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
ImageMagick before 7.0.8-55 has a use-after-free in DestroyStringInfo in MagickCore/string.c because the error manager is mishandled in coders/jpeg.c.
ImageMagick versiones anteriores a 7.0.8-55, presenta una vulnerabilidad de uso de la memoria previamente liberada de la funciĆ³n DestroyStringInfo en el archivo MagickCore/string.c porque el administrador de errores es manejado inapropiadamente en el archivo coders/jpeg.c.
ImageMagick is an image display and manipulation tool for the X Window System that can read and write multiple image formats. Issues addressed include buffer overflow, denial of service, double free, information leakage, null pointer, out of bounds read, out of bounds write, and use-after-free vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-10-14 CVE Reserved
- 2019-10-14 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-416: Use After Free
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=15827 | Issue Tracking |
URL | Date | SRC |
---|---|---|
https://github.com/ImageMagick/ImageMagick/issues/1641 | 2024-08-05 |
URL | Date | SRC |
---|---|---|
https://github.com/ImageMagick/ImageMagick/commit/39f226a9c137f547e12afde972eeba7551124493 | 2021-04-20 | |
https://github.com/ImageMagick/ImageMagick/compare/7.0.8-54...7.0.8-55 | 2021-04-20 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2019-17541 | 2020-03-31 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1767087 | 2020-03-31 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Imagemagick Search vendor "Imagemagick" | Imagemagick Search vendor "Imagemagick" for product "Imagemagick" | < 6.9.10-55 Search vendor "Imagemagick" for product "Imagemagick" and version " < 6.9.10-55" | - |
Affected
| ||||||
Imagemagick Search vendor "Imagemagick" | Imagemagick Search vendor "Imagemagick" for product "Imagemagick" | >= 7.0.0-0 < 7.0.8-55 Search vendor "Imagemagick" for product "Imagemagick" and version " >= 7.0.0-0 < 7.0.8-55" | - |
Affected
|