PublicDateAtUSN: 2018-10-20 Candidate: CVE-2018-18544 PublicDate: 2018-10-21 01:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18544 https://ubuntu.com/security/notices/USN-4034-1 Description: There is a memory leak in the function WriteMSLImage of coders/msl.c in ImageMagick 7.0.8-13 Q16, and the function ProcessMSLScript of coders/msl.c in GraphicsMagick before 1.3.31. Ubuntu-Description: Notes: Bugs: https://github.com/ImageMagick/ImageMagick/issues/1360 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_imagemagick: upstream: https://github.com/ImageMagick/ImageMagick6/commit/bb77f9e905597c7ab1e92042c7de418d999b00bf upstream_imagemagick: needs-triage precise/esm_imagemagick: DNE trusty_imagemagick: ignored (reached end-of-life) trusty/esm_imagemagick: DNE (trusty was needed) xenial_imagemagick: not-affected (code not present) esm-infra/xenial_imagemagick: not-affected (code not present) bionic_imagemagick: released (8:6.9.7.4+dfsg-16ubuntu6.7) cosmic_imagemagick: released (8:6.9.10.8+dfsg-1ubuntu2.2) disco_imagemagick: not-affected (8:6.9.10.14+dfsg-7ubuntu2) devel_imagemagick: not-affected (8:6.9.10.14+dfsg-7ubuntu2)