CVE-2019-13135: Canonical Ubuntu Linux

High severity, CVSS 8.8. EPSS: 3.3% chance of exploitation in the next 30 days.

ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function ReadCUTImage in coders/cut.c.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only; version 19.10 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
  • F5 BIG-IP Application Acceleration Manager: from 11.5.2, before 11.6.5.2 (fixed in 11.6.5.2); from 12.1.0, before 12.1.5.2 (fixed in 12.1.5.2); from 13.1.0, before 13.1.3.4 (fixed in 13.1.3.4); from 14.0.0, before 14.1.2.5 (fixed in 14.1.2.5); from 15.0.0, before 15.0.1.3 (fixed in 15.0.1.3); from 15.1.0, before 15.1.0.2 (fixed in 15.1.0.2)
  • F5 BIG-IP Webaccelerator: from 11.5.2, before 11.6.5.2 (fixed in 11.6.5.2); from 12.1.0, before 12.1.5.2 (fixed in 12.1.5.2); from 13.1.0, before 13.1.3.4 (fixed in 13.1.3.4); from 14.0.0, before 14.1.2.5 (fixed in 14.1.2.5); from 15.0.0, before 15.0.1.3 (fixed in 15.0.1.3); from 15.1.0, before 15.1.0.2 (fixed in 15.1.0.2)
  • ImageMagick ImageMagick: before 6.9.10-50 (fixed in 6.9.10-50); from 7.0.0-0, before 7.0.8-50 (fixed in 7.0.8-50)

Published 2019-07-01. Last modified 2026-06-17.