ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function ReadCUTImage in coders/cut.c.
{
"unresolved_ranges": [
{
"cpe": "cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "11.5.2"
},
{
"fixed": "11.6.5.2"
},
{
"introduced": "12.1.0"
},
{
"fixed": "12.1.5.2"
},
{
"introduced": "13.1.0"
},
{
"fixed": "13.1.3.4"
},
{
"introduced": "14.0.0"
},
{
"fixed": "14.1.2.5"
},
{
"introduced": "15.0.0"
},
{
"fixed": "15.0.1.3"
},
{
"introduced": "15.1.0"
},
{
"fixed": "15.1.0.2"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "11.5.2"
},
{
"fixed": "11.6.5.2"
},
{
"introduced": "12.1.0"
},
{
"fixed": "12.1.5.2"
},
{
"introduced": "13.1.0"
},
{
"fixed": "13.1.3.4"
},
{
"introduced": "14.0.0"
},
{
"fixed": "14.1.2.5"
},
{
"introduced": "15.0.0"
},
{
"fixed": "15.0.1.3"
},
{
"introduced": "15.1.0"
},
{
"fixed": "15.1.0.2"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*",
"extracted_events": [
{
"last_affected": "16.04"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*",
"extracted_events": [
{
"last_affected": "18.04"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "19.04"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "19.10"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "10.0"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "8.0"
}
],
"source": "CPE_FIELD"
},
{
"cpe": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*",
"extracted_events": [
{
"last_affected": "9.0"
}
],
"source": "CPE_FIELD"
}
]
}{
"cpe": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "7.0.0-0"
},
{
"fixed": "7.0.8-50"
}
],
"source": [
"CPE_FIELD",
"REFERENCES"
]
}"2026-04-11T21:44:56Z"
[
{
"signature_version": "v1",
"digest": {
"function_hash": "253619741159940371167142962521459300988",
"length": 8494.0
},
"id": "CVE-2019-13135-545b2366",
"signature_type": "Function",
"target": {
"file": "coders/cut.c",
"function": "ReadCUTImage"
},
"source": "https://github.com/imagemagick/imagemagick/commit/cdb383749ef7b68a38891440af8cc23e0115306d",
"deprecated": false
},
{
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"61892764038983991119490552154498627512",
"321170647698694715945998436878904534070",
"331024487043675496452624402612941408540",
"290448946013816365424048819710854145874"
]
},
"id": "CVE-2019-13135-8a175513",
"signature_type": "Line",
"target": {
"file": "coders/cut.c"
},
"source": "https://github.com/imagemagick/imagemagick/commit/cdb383749ef7b68a38891440af8cc23e0115306d",
"deprecated": false
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-13135.json"
{
"cpe": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "6.9.10-50"
}
],
"source": [
"CPE_FIELD",
"REFERENCES"
]
}"2026-04-11T21:44:56Z"
[
{
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"61892764038983991119490552154498627512",
"321170647698694715945998436878904534070",
"331024487043675496452624402612941408540",
"290448946013816365424048819710854145874"
]
},
"id": "CVE-2019-13135-6a454bb3",
"signature_type": "Line",
"target": {
"file": "coders/cut.c"
},
"source": "https://github.com/imagemagick/imagemagick6/commit/1e59b29e520d2beab73e8c78aacd5f1c0d76196d",
"deprecated": false
},
{
"signature_version": "v1",
"digest": {
"function_hash": "305522677277587060832954439036619785451",
"length": 8425.0
},
"id": "CVE-2019-13135-e9b5a95d",
"signature_type": "Function",
"target": {
"file": "coders/cut.c",
"function": "ReadCUTImage"
},
"source": "https://github.com/imagemagick/imagemagick6/commit/1e59b29e520d2beab73e8c78aacd5f1c0d76196d",
"deprecated": false
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-13135.json"