Bugzilla – Bug 1081303
VUL-1: ImageMagick: CVE-2018-6930: ImageMagick: Stack-based buffer over-read in the ComputeResizeImage function
Last modified: 2018-04-18 11:09:23 UTC
rh#1544789 A stack-based buffer over-read in the ComputeResizeImage function in the MagickCore/accelerate.c file of ImageMagick 7.0.7-22 allows a remote attacker to cause a denial of service (application crash) via a maliciously crafted pict file. References: https://bugzilla.redhat.com/show_bug.cgi?id=1544789 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-6930 http://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-6930.html http://www.cvedetails.com/cve/CVE-2018-6930/ https://github.com/ImageMagick/ImageMagick/issues/967
I do not see the code anywhere in ImageMagick 6 versions we maintain, considering unaffected. Even ImageMagick-7.0.7-25 contained in SUSE:SLE-15:GA has the fix in already.