PublicDateAtUSN: 2019-03-23 Candidate: CVE-2019-9956 PublicDate: 2019-03-24 00:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9956 https://ubuntu.com/security/notices/USN-4034-1 Description: In ImageMagick 7.0.8-35 Q16, there is a stack-based buffer overflow in the function PopHexPixel of coders/ps.c, which allows an attacker to cause a denial of service or code execution via a crafted image file. Ubuntu-Description: Notes: Bugs: https://github.com/ImageMagick/ImageMagick/issues/1523 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=925395 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_imagemagick: upstream: https://github.com/ImageMagick/ImageMagick/commit/34a6a5a45e83a4af852090b4e43f168a380df979 upstream: https://github.com/ImageMagick/ImageMagick6/commit/90401e430840c5ff31ad870f4370bbda1318ac94 upstream_imagemagick: released (8:6.9.10.23+dfsg-2.1) precise/esm_imagemagick: DNE trusty_imagemagick: ignored (reached end-of-life) trusty/esm_imagemagick: DNE (trusty was needed) xenial_imagemagick: released (8:6.8.9.9-7ubuntu5.14) esm-infra/xenial_imagemagick: released (8:6.8.9.9-7ubuntu5.14) bionic_imagemagick: released (8:6.9.7.4+dfsg-16ubuntu6.7) cosmic_imagemagick: released (8:6.9.10.8+dfsg-1ubuntu2.2) disco_imagemagick: released (8:6.9.10.14+dfsg-7ubuntu2.2) devel_imagemagick: released (8:6.9.10.23+dfsg-2.1ubuntu1)