Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-9133

Опубликовано: 30 мар. 2018
Источник: debian

Описание

ImageMagick 7.0.7-26 Q16 has excessive iteration in the DecodeLabImage and EncodeLabImage functions (coders/tiff.c), which results in a hang (tens of minutes) with a tiny PoC file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tiff file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
imagemagickfixed8:6.9.10.2+dfsg-1experimentalpackage
imagemagickfixed8:6.9.10.2+dfsg-2package
imagemagickignoredjessiepackage
imagemagickignoredwheezypackage

Примечания

  • https://github.com/ImageMagick/ImageMagick/issues/1072

  • IM6: https://github.com/ImageMagick/ImageMagick/commit/089fca04e0130549fa15f48ace3f56e30a06049a

  • IM7: https://github.com/ImageMagick/ImageMagick/commit/19b96ba61431914e2ac316b72c0789965f2b7c09

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

ImageMagick 7.0.7-26 Q16 has excessive iteration in the DecodeLabImage and EncodeLabImage functions (coders/tiff.c), which results in a hang (tens of minutes) with a tiny PoC file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tiff file.

CVSS3: 3.3
redhat
больше 7 лет назад

ImageMagick 7.0.7-26 Q16 has excessive iteration in the DecodeLabImage and EncodeLabImage functions (coders/tiff.c), which results in a hang (tens of minutes) with a tiny PoC file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tiff file.

CVSS3: 6.5
nvd
больше 7 лет назад

ImageMagick 7.0.7-26 Q16 has excessive iteration in the DecodeLabImage and EncodeLabImage functions (coders/tiff.c), which results in a hang (tens of minutes) with a tiny PoC file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tiff file.

CVSS3: 6.5
github
около 3 лет назад

ImageMagick 7.0.7-26 Q16 has excessive iteration in the DecodeLabImage and EncodeLabImage functions (coders/tiff.c), which results in a hang (tens of minutes) with a tiny PoC file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tiff file.

CVSS3: 6.5
fstec
больше 7 лет назад

Уязвимость функций DecodeLabImage и EncodeLabImage компонента coders/tiff.c консольного графического редактора ImageMagick, связанная с чрезмерным итерированием, позволяющая нарушителю вызвать отказ в обслуживании