Back

MEDIUM

ImageMagick: denial of service in cineon parsing component

Published Apr 23, 2019

Description

The cineon parsing component in ImageMagick 7.0.8-26 Q16 allows attackers to cause a denial-of-service (uncontrolled resource consumption) by crafting a Cineon image with an incorrect claimed image size. This occurs because ReadCINImage in coders/cin.c lacks a check for insufficient image data in a file.

Affected products

Remediation

Red Hat mitigation

You can configure a security policy that limits the disk resource usage when running ImageMagick. Edit /etc/ImageMagick/policy.xml with: ``` <policymap> ... <policy domain="resource" name="disk" value="1GiB"/> ... </policymap> ```

References (15)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Apr 23, 2019
Updated Aug 4, 2024
Reserved Apr 23, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Low
Public date Feb 5, 2019
Bugzilla 1707770

ENISA EUVD

Assigner mitre
Published Apr 23, 2019
Updated Aug 4, 2024

GitHub

No data