PublicDateAtUSN: 2018-10-07 Candidate: CVE-2018-18024 PublicDate: 2018-10-07 18:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18024 https://ubuntu.com/security/notices/USN-4034-1 Description: In ImageMagick 7.0.8-13 Q16, there is an infinite loop in the ReadBMPImage function of the coders/bmp.c file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. Ubuntu-Description: Notes: Bugs: https://github.com/ImageMagick/ImageMagick/issues/1337 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_imagemagick: upstream: https://github.com/ImageMagick/ImageMagick/commit/948f1c86d649a29df08a38d2ff8b91cdf3e92b82 upstream: https://github.com/ImageMagick/ImageMagick6/commit/b268ce7a59440972f4476b9fd98104b6a836d971 upstream_imagemagick: needs-triage precise/esm_imagemagick: DNE trusty_imagemagick: ignored (reached end-of-life) trusty/esm_imagemagick: DNE (trusty was needed) xenial_imagemagick: released (8:6.8.9.9-7ubuntu5.14) esm-infra/xenial_imagemagick: released (8:6.8.9.9-7ubuntu5.14) bionic_imagemagick: released (8:6.9.7.4+dfsg-16ubuntu6.7) cosmic_imagemagick: released (8:6.9.10.8+dfsg-1ubuntu2.2) disco_imagemagick: not-affected (8:6.9.10.14+dfsg-7ubuntu2) devel_imagemagick: not-affected (8:6.9.10.14+dfsg-7ubuntu2)