VulnerabilityModified
CVE-2019-14981
In ImageMagick 7.x before 7.0.8-41 and 6.x before 6.9.10-41, there is a divide-by-zero vulnerability in the MeanShiftImage function.
MEDIUM 6.5EPSS 2.69%
Does this matter?
Lower severity and a low EPSS score (2.69%). Track it; it rarely justifies an emergency change on its own.
Description
In ImageMagick 7.x before 7.0.8-41 and 6.x before 6.9.10-41, there is a divide-by-zero vulnerability in the MeanShiftImage function. It allows an attacker to cause a denial of service by sending a crafted file.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 2.69% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-369
- Affected
- imagemagick/imagemagick · debian/debian linux · canonical/ubuntu linux · opensuse/leap
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00040.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00042.htmlMailing List, Third Party Advisory
- https://github.com/ImageMagick/ImageMagick/commit/a77d8d97f5a7bced0468f0b08798c83fb67427bcPatch, Third Party Advisory
- https://github.com/ImageMagick/ImageMagick/issues/1552Patch, Third Party Advisory
- https://github.com/ImageMagick/ImageMagick6/commit/b522d2d857d2f75b659936b59b0da9df1682c256Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/10/msg00028.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/08/msg00030.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/4192-1/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4712Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00040.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00042.htmlMailing List, Third Party Advisory
- https://github.com/ImageMagick/ImageMagick/commit/a77d8d97f5a7bced0468f0b08798c83fb67427bcPatch, Third Party Advisory
- https://github.com/ImageMagick/ImageMagick/issues/1552Patch, Third Party Advisory
- https://github.com/ImageMagick/ImageMagick6/commit/b522d2d857d2f75b659936b59b0da9df1682c256Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/10/msg00028.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/08/msg00030.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/4192-1/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4712Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.