Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-5508

Опубликовано: 24 мар. 2017
Источник: debian
EPSS Низкий

Описание

Heap-based buffer overflow in the PushQuantumPixel function in ImageMagick before 6.9.7-3 and 7.x before 7.0.4-3 allows remote attackers to cause a denial of service (application crash) via a crafted TIFF file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
imagemagickfixed8:6.9.7.4+dfsg-1package

Примечания

  • https://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=31161

  • https://www.openwall.com/lists/oss-security/2017/01/16/6

  • https://github.com/ImageMagick/ImageMagick/commit/379e21cd32483df6e128147af3bc4ce1f82eb9c4

EPSS

Процентиль: 67%
0.00544
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 9 лет назад

Heap-based buffer overflow in the PushQuantumPixel function in ImageMagick before 6.9.7-3 and 7.x before 7.0.4-3 allows remote attackers to cause a denial of service (application crash) via a crafted TIFF file.

CVSS3: 5.3
redhat
около 9 лет назад

Heap-based buffer overflow in the PushQuantumPixel function in ImageMagick before 6.9.7-3 and 7.x before 7.0.4-3 allows remote attackers to cause a denial of service (application crash) via a crafted TIFF file.

CVSS3: 5.5
nvd
почти 9 лет назад

Heap-based buffer overflow in the PushQuantumPixel function in ImageMagick before 6.9.7-3 and 7.x before 7.0.4-3 allows remote attackers to cause a denial of service (application crash) via a crafted TIFF file.

CVSS3: 5.5
github
больше 3 лет назад

Heap-based buffer overflow in the PushQuantumPixel function in ImageMagick before 6.9.7-3 and 7.x before 7.0.4-3 allows remote attackers to cause a denial of service (application crash) via a crafted TIFF file.

suse-cvrf
почти 9 лет назад

Security update for ImageMagick

EPSS

Процентиль: 67%
0.00544
Низкий