Candidate: CVE-2018-9135 PublicDate: 2018-03-30 08:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-9135 Description: In ImageMagick 7.0.7-24 Q16, there is a heap-based buffer over-read in IsWEBPImageLossless in coders/webp.c. Ubuntu-Description: Notes: mdeslaur> webp not enabled Bugs: https://github.com/ImageMagick/ImageMagick/issues/1009 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_imagemagick: upstream: https://github.com/ImageMagick/ImageMagick/commits/4f7196b0b7539b113f2580b6a77aa496813d8899 upstream_imagemagick: needs-triage precise/esm_imagemagick: DNE trusty_imagemagick: not-affected (code not built) trusty/esm_imagemagick: DNE (trusty was not-affected [code not built]) xenial_imagemagick: not-affected (code not built) esm-infra/xenial_imagemagick: not-affected (code not built) artful_imagemagick: not-affected (code not built) bionic_imagemagick: not-affected (code not built) devel_imagemagick: not-affected (code not built)