Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-16323

Опубликовано: 01 сент. 2018
Источник: debian
EPSS Высокий

Описание

ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If the affected code is used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
imagemagickfixed8:6.9.10.14+dfsg-1package
imagemagicknot-affectedstretchpackage
imagemagicknot-affectedjessiepackage

Примечания

  • https://github.com/ImageMagick/ImageMagick/commit/216d117f05bff87b9dc4db55a1b1fadb38bcb786

  • ImageMagick6: https://github.com/ImageMagick/ImageMagick6/commit/57565dace66d550042522e203f522da711d551a6

EPSS

Процентиль: 99%
0.8778
Высокий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If the affected code is used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data.

CVSS3: 4.3
redhat
больше 7 лет назад

ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If the affected code is used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data.

CVSS3: 6.5
nvd
больше 7 лет назад

ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If the affected code is used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data.

suse-cvrf
больше 7 лет назад

Security update for GraphicsMagick

CVSS3: 6.5
github
больше 3 лет назад

ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If the affected code is used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data.

EPSS

Процентиль: 99%
0.8778
Высокий