Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-14980

Опубликовано: 12 авг. 2019
Источник: debian
EPSS Низкий

Описание

In ImageMagick 7.x before 7.0.8-42 and 6.x before 6.9.10-42, there is a use after free vulnerability in the UnmapBlob function that allows an attacker to cause a denial of service by sending a crafted file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
imagemagicknot-affectedpackage

Примечания

  • https://github.com/ImageMagick/ImageMagick6/issues/43

  • Introduced in https://github.com/ImageMagick/ImageMagick6/commit/6f29b3755748a899145b639195dd3bc640d36bb4 (6.9.10-24)

  • Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/614a257295bdcdeda347086761062ac7658b6830 (6.9.10-42)

EPSS

Процентиль: 42%
0.00197
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 6 лет назад

In ImageMagick 7.x before 7.0.8-42 and 6.x before 6.9.10-42, there is a use after free vulnerability in the UnmapBlob function that allows an attacker to cause a denial of service by sending a crafted file.

CVSS3: 5.9
redhat
около 6 лет назад

In ImageMagick 7.x before 7.0.8-42 and 6.x before 6.9.10-42, there is a use after free vulnerability in the UnmapBlob function that allows an attacker to cause a denial of service by sending a crafted file.

CVSS3: 6.5
nvd
почти 6 лет назад

In ImageMagick 7.x before 7.0.8-42 and 6.x before 6.9.10-42, there is a use after free vulnerability in the UnmapBlob function that allows an attacker to cause a denial of service by sending a crafted file.

CVSS3: 6.5
github
около 3 лет назад

In ImageMagick 7.x before 7.0.8-42 and 6.x before 6.9.10-42, there is a use after free vulnerability in the UnmapBlob function that allows an attacker to cause a denial of service by sending a crafted file.

suse-cvrf
больше 5 лет назад

Security update for ImageMagick

EPSS

Процентиль: 42%
0.00197
Низкий