Candidate: CVE-2019-13133 PublicDate: 2019-07-01 20:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13133 Description: ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadBMPImage in coders/bmp.c. Ubuntu-Description: Notes: mdeslaur> introduced by: mdeslaur> https://github.com/ImageMagick/ImageMagick/commit/3b48d20df53ad048af05107aa1850c344466b082 mdeslaur> in imagemagick6, the equivalent patch did not introduce the mdeslaur> issue, so not affected: mdeslaur> https://github.com/ImageMagick/ImageMagick6/commit/210474b2fac6a661bfa7ed563213920e93e76395 Bugs: https://github.com/ImageMagick/ImageMagick/issues/1600 Priority: negligible Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [5.5 MEDIUM] nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [5.5 MEDIUM] Patches_imagemagick: upstream: https://github.com/ImageMagick/ImageMagick/commit/fe3066122ef72c82415811d25e9e3fad622c0a99 upstream_imagemagick: not-affected (debian: Only affects Imagemagick 7) precise/esm_imagemagick: DNE trusty_imagemagick: ignored (out of standard support) trusty/esm_imagemagick: DNE xenial_imagemagick: not-affected (8:6.8.9.9-7ubuntu5.14) esm-infra/xenial_imagemagick: not-affected (8:6.8.9.9-7ubuntu5.14) bionic_imagemagick: not-affected (8:6.9.7.4+dfsg-16ubuntu6.7) cosmic_imagemagick: not-affected (8:6.9.10.8+dfsg-1ubuntu2.2) disco_imagemagick: not-affected (8:6.9.10.14+dfsg-7ubuntu2.2) devel_imagemagick: not-affected (8:6.9.10.23+dfsg-2.1ubuntu3)