ImageMagick is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information that may aid in further attacks. Failed exploit attempts may result in denial-of-service conditions.
ImageMagick 7.0.6-10 Q16 is vulnerable; other versions may also be affected.
Information
Redhat Enterprise Linux 6
Redhat Enterprise Linux 5
ImageMagick ImageMagick 7.0.6-10 Q16
Exploit
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
References:
- memory leak in ReadMATImage #691 (ImageMagick)
- ImageMagick Homepage (ImageMagick)
- Bug 1534732 - (CVE-2017-18029) CVE-2017-18029 ImageMagick: memory leak in the f (Redhat)
- CVE-2017-18029 (Redhat)