Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-10928

Опубликовано: 05 июл. 2017
Источник: debian
EPSS Низкий

Описание

In ImageMagick 7.0.6-0, a heap-based buffer over-read in the GetNextToken function in token.c allows remote attackers to obtain sensitive information from process memory or possibly have unspecified other impact via a crafted SVG document that is mishandled in the GetUserSpaceCoordinateValue function in coders/svg.c.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
imagemagickfixed8:6.9.7.4+dfsg-12package

Примечания

  • https://github.com/ImageMagick/ImageMagick/issues/539

EPSS

Процентиль: 78%
0.01184
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 8 лет назад

In ImageMagick 7.0.6-0, a heap-based buffer over-read in the GetNextToken function in token.c allows remote attackers to obtain sensitive information from process memory or possibly have unspecified other impact via a crafted SVG document that is mishandled in the GetUserSpaceCoordinateValue function in coders/svg.c.

CVSS3: 3.3
redhat
больше 8 лет назад

In ImageMagick 7.0.6-0, a heap-based buffer over-read in the GetNextToken function in token.c allows remote attackers to obtain sensitive information from process memory or possibly have unspecified other impact via a crafted SVG document that is mishandled in the GetUserSpaceCoordinateValue function in coders/svg.c.

CVSS3: 8.8
nvd
больше 8 лет назад

In ImageMagick 7.0.6-0, a heap-based buffer over-read in the GetNextToken function in token.c allows remote attackers to obtain sensitive information from process memory or possibly have unspecified other impact via a crafted SVG document that is mishandled in the GetUserSpaceCoordinateValue function in coders/svg.c.

CVSS3: 8.8
github
больше 3 лет назад

In ImageMagick 7.0.6-0, a heap-based buffer over-read in the GetNextToken function in token.c allows remote attackers to obtain sensitive information from process memory or possibly have unspecified other impact via a crafted SVG document that is mishandled in the GetUserSpaceCoordinateValue function in coders/svg.c.

suse-cvrf
больше 7 лет назад

Security update for ImageMagick

EPSS

Процентиль: 78%
0.01184
Низкий