Описание
Integer overflow in coders/icon.c in ImageMagick 6.9.1-3 and later allows remote attackers to cause a denial of service (application crash) via a crafted length value, which triggers a buffer overflow.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
imagemagick | fixed | 8:6.8.9.9-7 | package | |
imagemagick | fixed | 8:6.8.9.9-5+deb8u1 | jessie | package |
imagemagick | fixed | 8:6.7.7.10-5+deb7u4 | wheezy | package |
Примечания
https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1459747
https://github.com/ImageMagick/ImageMagick/commit/0f6fc2d5bf8f500820c3dbcf0d23ee14f2d9f734
https://www.openwall.com/lists/oss-security/2015/10/07/2
https://www.openwall.com/lists/oss-security/2016/02/22/4
The issue is only exploitable on 32 bit architectures.
EPSS
Связанные уязвимости
Integer overflow in coders/icon.c in ImageMagick 6.9.1-3 and later allows remote attackers to cause a denial of service (application crash) via a crafted length value, which triggers a buffer overflow.
Integer overflow in coders/icon.c in ImageMagick 6.9.1-3 and later allows remote attackers to cause a denial of service (application crash) via a crafted length value, which triggers a buffer overflow.
Integer overflow in coders/icon.c in ImageMagick 6.9.1-3 and later allows remote attackers to cause a denial of service (application crash) via a crafted length value, which triggers a buffer overflow.
Integer overflow in coders/icon.c in ImageMagick 6.9.1-3 and later allows remote attackers to cause a denial of service (application crash) via a crafted length value, which triggers a buffer overflow.
Уязвимость консольного графического редактора ImageMagick, позволяющая нарушителю вызвать отказ в обслуживании
EPSS