Uncontrolled Resource Consumption ('Resource Exhaustion') Affecting rmagick package, versions <5.3.0
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.05% (19th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RUBY-RMAGICK-6039897
- published 31 Oct 2023
- disclosed 30 Oct 2023
- credit Nick Browning
Introduced: 30 Oct 2023
CVE-2023-5349 Open this link in a new tabHow to fix?
Upgrade rmagick
to version 5.3.0 or higher.
Overview
rmagick is an an interface between Ruby and ImageMagick.
Affected versions of this package are vulnerable to Uncontrolled Resource Consumption ('Resource Exhaustion') via the DrawOptions_initialize
function in rmdraw.c
. An attacker can cause a denial of service by exhausting memory resources.
References
CVSS Scores
version 3.1