A memory leak flaw was found in ruby-magick, an interface between Ruby and ImageMagick. This issue can lead to a denial of service (DOS) by memory exhaustion.
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
Link | Tags |
---|---|
https://access.redhat.com/security/cve/CVE-2023-5349 | third party advisory vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=2247064 | third party advisory issue tracking |
https://github.com/rmagick/rmagick/issues/1401 | third party advisory issue tracking exploit |
https://github.com/rmagick/rmagick/pull/1406 | patch |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S3XMQ2KWPYGT447EKPENGXXHKAQ5NUWF/ |