Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-11750

Опубликовано: 30 июл. 2017
Источник: debian

Описание

The ReadOneJNGImage function in coders/png.c in ImageMagick 6.9.9-4 and 7.0.6-4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
imagemagickfixed8:6.9.7.4+dfsg-16package
imagemagicknot-affectedstretchpackage
imagemagicknot-affectedjessiepackage
imagemagicknot-affectedwheezypackage

Примечания

  • https://github.com/ImageMagick/ImageMagick/issues/632

  • Introduced by: https://github.com/ImageMagick/ImageMagick/commit/8cc53f1d8946bad2a2c62e084aaf956d4d889f08

  • Introduced by (ImageMagick-6): https://github.com/ImageMagick/ImageMagick/commit/3cba1bb43acf5b3cba7388f67bf87b6f192138f0

  • Fixed by: https://github.com/ImageMagick/ImageMagick/commit/1828667e81e53345cfb3eb46539d78757f1aa680

  • Fixed by (ImageMagick-6): https://github.com/ImageMagick/ImageMagick/commit/253d56027765dcbd8d6bc2bbd7d59aa41dab60e7

  • Issue introduced by the original patch for https://github.com/ImageMagick/ImageMagick/issues/618

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 8 лет назад

The ReadOneJNGImage function in coders/png.c in ImageMagick 6.9.9-4 and 7.0.6-4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

CVSS3: 5.5
redhat
больше 8 лет назад

The ReadOneJNGImage function in coders/png.c in ImageMagick 6.9.9-4 and 7.0.6-4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

CVSS3: 6.5
nvd
больше 8 лет назад

The ReadOneJNGImage function in coders/png.c in ImageMagick 6.9.9-4 and 7.0.6-4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

CVSS3: 6.5
github
больше 3 лет назад

The ReadOneJNGImage function in coders/png.c in ImageMagick 6.9.9-4 and 7.0.6-4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

fstec
больше 8 лет назад

Уязвимость функции ReadOneJNGImage в coders/png.c консольного графического редактора ImageMagick, позволяющая нарушителю вызвать отказ в обслуживании