Vulnerability record · CVE-2018-15607 · published 21 August 2018
CVE-2018-15607: Imagemagick uncontrolled resource consumption vulnerability
Imagemagick · Imagemagick
In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.
Description
In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/105137 | Third Party AdvisoryVDB Entry |
| https://github.com/ImageMagick/ImageMagick/issues/1255 | ExploitThird Party Advisory |
| https://usn.ubuntu.com/4034-1/ | |
| http://www.securityfocus.com/bid/105137 | Third Party AdvisoryVDB Entry |
| https://github.com/ImageMagick/ImageMagick/issues/1255 | ExploitThird Party Advisory |
| https://usn.ubuntu.com/4034-1/ |
Track CVE-2018-15607 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-15607), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.