CVE Vulnerabilities

CVE-2018-10177

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Apr 16, 2018 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
3.3 LOW
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Ubuntu
LOW

In ImageMagick 7.0.7-28, there is an infinite loop in the ReadOneMNGImage function of the coders/png.c file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted mng file.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Imagemagick Imagemagick 7.0.7-28 (including) 7.0.7-28 (including)
Red Hat Enterprise Linux 7 RedHat autotrace-0:0.31.1-38.el7 *
Red Hat Enterprise Linux 7 RedHat emacs-1:24.3-23.el7 *
Red Hat Enterprise Linux 7 RedHat ImageMagick-0:6.9.10.68-3.el7 *
Red Hat Enterprise Linux 7 RedHat inkscape-0:0.92.2-3.el7 *
Imagemagick Ubuntu artful *
Imagemagick Ubuntu bionic *
Imagemagick Ubuntu devel *
Imagemagick Ubuntu trusty *
Imagemagick Ubuntu xenial *

References