Описание
ImageMagick has Possible Heap Information Disclosure in PSD ZIP Decompression
Description
A heap information disclosure vulnerability exists in ImageMagick's PSD (Adobe Photoshop) format handler. When processing a maliciously crafted PSD file containing ZIP-compressed layer data that decompresses to less than the expected size, uninitialized heap memory is leaked into the output image.
Expected Impact
Information disclosure leading to potential exposure of sensitive data from server memory.
Пакеты
Magick.NET-Q16-AnyCPU
< 14.10.3
14.10.3
Magick.NET-Q16-HDRI-AnyCPU
< 14.10.3
14.10.3
Magick.NET-Q16-HDRI-OpenMP-arm64
< 14.10.3
14.10.3
Magick.NET-Q16-HDRI-OpenMP-x64
< 14.10.3
14.10.3
Magick.NET-Q16-HDRI-arm64
< 14.10.3
14.10.3
Magick.NET-Q16-HDRI-x64
< 14.10.3
14.10.3
Magick.NET-Q16-HDRI-x86
< 14.10.3
14.10.3
Magick.NET-Q16-OpenMP-arm64
< 14.10.3
14.10.3
Magick.NET-Q16-OpenMP-x64
< 14.10.3
14.10.3
Magick.NET-Q16-arm64
< 14.10.3
14.10.3
Magick.NET-Q16-x64
< 14.10.3
14.10.3
Magick.NET-Q16-x86
< 14.10.3
14.10.3
Magick.NET-Q8-AnyCPU
< 14.10.3
14.10.3
Magick.NET-Q8-OpenMP-arm64
< 14.10.3
14.10.3
Magick.NET-Q8-OpenMP-x64
< 14.10.3
14.10.3
Magick.NET-Q8-arm64
< 14.10.3
14.10.3
Magick.NET-Q8-x86
< 14.10.3
14.10.3
Связанные уязвимости
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap information disclosure vulnerability exists in ImageMagick's PSD (Adobe Photoshop) format handler. When processing a maliciously crafted PSD file containing ZIP-compressed layer data that decompresses to less than the expected size, uninitialized heap memory is leaked into the output image. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap information disclosure vulnerability exists in ImageMagick's PSD (Adobe Photoshop) format handler. When processing a maliciously crafted PSD file containing ZIP-compressed layer data that decompresses to less than the expected size, uninitialized heap memory is leaked into the output image. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
ImageMagick is free and open-source software used for editing and mani ...