ImageMagick before 7.0.9-0 allows remote attackers to cause a denial of service because XMLPARSEHUGE is not properly restricted in coders/svg.c, related to SVG and libxml2.
[
{
"id": "CVE-2019-18853-2ca39486",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "coders/svg.c"
},
"source": "https://github.com/imagemagick/imagemagick/commit/ec9c8944af2bfc65c697ca44f93a727a99b405f1",
"digest": {
"line_hashes": [
"188741590478884437596531523740631762966",
"207696325795588786314595779811755654804",
"270257041119015477781781183334268304926",
"187729546429486020281855056877847785694",
"245905222275880872090317696564746571357",
"213891789193319231144477660689705213191",
"72972779699929256110823398031095212758",
"31824464683656104232536516127433142417",
"298347910662461208257590530542086361756",
"160962854358945914580338740688618188563",
"155965701973401213656064473986686025001",
"71263694157038042163817343759041450800",
"25303115475014395364713981043379266209"
],
"threshold": 0.9
},
"signature_type": "Line"
},
{
"id": "CVE-2019-18853-64344b59",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "coders/svg.c",
"function": "ReadSVGImage"
},
"source": "https://github.com/imagemagick/imagemagick/commit/ec9c8944af2bfc65c697ca44f93a727a99b405f1",
"digest": {
"length": 11179.0,
"function_hash": "169033915039393173920607896337339071194"
},
"signature_type": "Function"
}
]