Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-20467

Опубликовано: 26 дек. 2018
Источник: debian
EPSS Низкий

Описание

In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an infinite loop and hang, with high CPU and memory consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
imagemagickfixed8:6.9.10.23+dfsg-1package
imagemagickignoredjessiepackage

Примечания

  • https://github.com/ImageMagick/ImageMagick/issues/1408

  • https://github.com/ImageMagick/ImageMagick/commit/db0add932fb850d762b02604ca3053b7d7ab6deb

  • https://github.com/ImageMagick/ImageMagick6/commit/4dd53a3f790147aaf18b2dd4d15f2a19f9432d3f

EPSS

Процентиль: 37%
0.00157
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 6 лет назад

In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an infinite loop and hang, with high CPU and memory consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.

CVSS3: 5.3
redhat
больше 6 лет назад

In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an infinite loop and hang, with high CPU and memory consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.

CVSS3: 6.5
nvd
больше 6 лет назад

In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an infinite loop and hang, with high CPU and memory consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.

suse-cvrf
больше 6 лет назад

Security update for GraphicsMagick

CVSS3: 6.5
github
около 3 лет назад

In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an infinite loop and hang, with high CPU and memory consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.

EPSS

Процентиль: 37%
0.00157
Низкий