An issue was discovered in ImageMagick 7.0.7-22 Q16. The IsWEBPImageLossless function in coders/webp.c allows attackers to cause a denial of service (segmentation violation) via a crafted file.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade imagemagick6 | Oct 1, 2024 | Feb 25, 2018 |
| Debian | — | Upgrade imagemagick | Jul 30, 2024 | Feb 25, 2018 |
| Oracle Solaris | — | Upgrade image/imagemagick to version 6.9.9.40-0.175.3.32.0.1.0 on Solaris 11.3 | May 16, 2018 | Feb 25, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 25, 2018 |
| Suse | — | Upgrade libmagick-develUpgrade libmagick-6_q16-3Upgrade imagemagick-config-6-upstreamUpgrade libmagickcore-6_q16-1-32bitUpgrade imagemagickUpgrade libmagickcore-6_q16-1Upgrade imagemagick-develUpgrade perl-perlmagickUpgrade imagemagick-config-6-suseUpgrade libmagickwand-6_q16-1 | Apr 4, 2018 | Feb 25, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub