Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-5240

Опубликовано: 27 фев. 2017
Источник: debian

Описание

The DrawDashPolygon function in magick/render.c in GraphicsMagick before 1.3.24 and the SVG renderer in ImageMagick allow remote attackers to cause a denial of service (infinite loop) by converting a circularly defined SVG file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
graphicsmagickfixed1.3.24-1package

Примечания

  • Fixed by: http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/ddc999ec896c

  • DLA-547-1 didn't fix this properly

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 9 лет назад

The DrawDashPolygon function in magick/render.c in GraphicsMagick before 1.3.24 and the SVG renderer in ImageMagick allow remote attackers to cause a denial of service (infinite loop) by converting a circularly defined SVG file.

redhat
почти 10 лет назад

The DrawDashPolygon function in magick/render.c in GraphicsMagick before 1.3.24 and the SVG renderer in ImageMagick allow remote attackers to cause a denial of service (infinite loop) by converting a circularly defined SVG file.

CVSS3: 5.5
nvd
почти 9 лет назад

The DrawDashPolygon function in magick/render.c in GraphicsMagick before 1.3.24 and the SVG renderer in ImageMagick allow remote attackers to cause a denial of service (infinite loop) by converting a circularly defined SVG file.

CVSS3: 5.5
github
больше 3 лет назад

The DrawDashPolygon function in magick/render.c in GraphicsMagick before 1.3.24 and the SVG renderer in ImageMagick allow remote attackers to cause a denial of service (infinite loop) by converting a circularly defined SVG file.

oracle-oval
больше 9 лет назад

ELSA-2016-1237: ImageMagick security update (IMPORTANT)