Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-0284

Опубликовано: 29 авг. 2022
Источник: debian

Описание

A heap-based-buffer-over-read flaw was found in ImageMagick's GetPixelAlpha() function of 'pixel-accessor.h'. This vulnerability is triggered when an attacker passes a specially crafted Tagged Image File Format (TIFF) image to convert it into a PICON file format. This issue can potentially lead to a denial of service and information disclosure.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
imagemagicknot-affectedpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2045943

  • https://github.com/ImageMagick/ImageMagick/issues/4729

  • https://github.com/ImageMagick/ImageMagick/commit/e50f19fd73c792ebe912df8ab83aa51a243a3da7

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 3 лет назад

A heap-based-buffer-over-read flaw was found in ImageMagick's GetPixelAlpha() function of 'pixel-accessor.h'. This vulnerability is triggered when an attacker passes a specially crafted Tagged Image File Format (TIFF) image to convert it into a PICON file format. This issue can potentially lead to a denial of service and information disclosure.

CVSS3: 5.1
redhat
около 4 лет назад

A heap-based-buffer-over-read flaw was found in ImageMagick's GetPixelAlpha() function of 'pixel-accessor.h'. This vulnerability is triggered when an attacker passes a specially crafted Tagged Image File Format (TIFF) image to convert it into a PICON file format. This issue can potentially lead to a denial of service and information disclosure.

CVSS3: 7.1
nvd
больше 3 лет назад

A heap-based-buffer-over-read flaw was found in ImageMagick's GetPixelAlpha() function of 'pixel-accessor.h'. This vulnerability is triggered when an attacker passes a specially crafted Tagged Image File Format (TIFF) image to convert it into a PICON file format. This issue can potentially lead to a denial of service and information disclosure.

suse-cvrf
почти 4 года назад

Security update for ImageMagick

suse-cvrf
почти 4 года назад

Security update for ImageMagick