PublicDateAtUSN: 2019-07-07 22:15:00 UTC Candidate: CVE-2019-13391 PublicDate: 2019-07-07 22:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13391 https://ubuntu.com/security/notices/USN-4192-1 Description: In ImageMagick 7.0.8-50 Q16, ComplexImages in MagickCore/fourier.c has a heap-based buffer over-read because of incorrect calls to GetCacheViewVirtualPixels. Ubuntu-Description: Notes: emitorino> "Patch is insufficient, and most likely broken. It is partly reverted by the CVE-2019-13308 patch, which seems to be the actual patch for this issue" mdeslaur> below is the CVE-2019-13308 commits. Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=931633 https://github.com/ImageMagick/ImageMagick/issues/1588 https://github.com/ImageMagick/ImageMagick/issues/1595 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_imagemagick: upstream: https://github.com/ImageMagick/ImageMagick6/commit/f6ffc702c6eecd963587273a429dcd608c648984 upstream: https://github.com/ImageMagick/ImageMagick6/commit/19651f3db63fa1511ed83a348c4c82fa553f8d01 upstream_imagemagick: released (7.0.8-59) precise/esm_imagemagick: DNE trusty_imagemagick: ignored (out of standard support) trusty/esm_imagemagick: DNE xenial_imagemagick: released (8:6.8.9.9-7ubuntu5.15) esm-infra/xenial_imagemagick: released (8:6.8.9.9-7ubuntu5.15) bionic_imagemagick: released (8:6.9.7.4+dfsg-16ubuntu6.8) cosmic_imagemagick: ignored (reached end-of-life) disco_imagemagick: released (8:6.9.10.14+dfsg-7ubuntu2.3) eoan_imagemagick: released (8:6.9.10.23+dfsg-2.1ubuntu3.1) devel_imagemagick: released (8:6.9.10.23+dfsg-2.1ubuntu9)