Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-5841

Опубликовано: 13 дек. 2016
Источник: debian
EPSS Средний

Описание

Integer overflow in MagickCore/profile.c in ImageMagick before 7.0.2-1 allows remote attackers to cause a denial of service (segmentation fault) or possibly execute arbitrary code via vectors involving the offset variable.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
imagemagickfixed8:6.9.6.2+dfsg-2package

Примечания

  • Details: https://www.openwall.com/lists/oss-security/2016/06/23/1

  • https://github.com/ImageMagick/ImageMagick/commit/d8ab7f046587f2e9f734b687ba7e6e10147c294b

  • Reproducer http://bugs.fi/media/afl/imagemagick/CVE-2016-5841.jpg

EPSS

Процентиль: 96%
0.2299
Средний

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 9 лет назад

Integer overflow in MagickCore/profile.c in ImageMagick before 7.0.2-1 allows remote attackers to cause a denial of service (segmentation fault) or possibly execute arbitrary code via vectors involving the offset variable.

CVSS3: 7.4
redhat
больше 9 лет назад

Integer overflow in MagickCore/profile.c in ImageMagick before 7.0.2-1 allows remote attackers to cause a denial of service (segmentation fault) or possibly execute arbitrary code via vectors involving the offset variable.

CVSS3: 9.8
nvd
около 9 лет назад

Integer overflow in MagickCore/profile.c in ImageMagick before 7.0.2-1 allows remote attackers to cause a denial of service (segmentation fault) or possibly execute arbitrary code via vectors involving the offset variable.

CVSS3: 9.8
github
больше 3 лет назад

Integer overflow in MagickCore/profile.c in ImageMagick before 7.0.2-1 allows remote attackers to cause a denial of service (segmentation fault) or possibly execute arbitrary code via vectors involving the offset variable.

suse-cvrf
больше 9 лет назад

Security update for ImageMagick

EPSS

Процентиль: 96%
0.2299
Средний