Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mp8r-x7vv-mqvq

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A flaw was found in ImageMagick 7.1.0-14 where it did not properly sanitize certain input before using it to invoke convert processes. This flaw allows an attacker to create a specially crafted image that leads to a use-after-free vulnerability when processed by ImageMagick. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

A flaw was found in ImageMagick 7.1.0-14 where it did not properly sanitize certain input before using it to invoke convert processes. This flaw allows an attacker to create a specially crafted image that leads to a use-after-free vulnerability when processed by ImageMagick. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

EPSS

Процентиль: 54%
0.00312
Низкий

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 4 лет назад

A flaw was found in ImageMagick where it did not properly sanitize certain input before using it to invoke convert processes. This flaw allows an attacker to create a specially crafted image that leads to a use-after-free vulnerability when processed by ImageMagick. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 5.3
redhat
около 4 лет назад

A flaw was found in ImageMagick where it did not properly sanitize certain input before using it to invoke convert processes. This flaw allows an attacker to create a specially crafted image that leads to a use-after-free vulnerability when processed by ImageMagick. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 7.8
nvd
около 4 лет назад

A flaw was found in ImageMagick where it did not properly sanitize certain input before using it to invoke convert processes. This flaw allows an attacker to create a specially crafted image that leads to a use-after-free vulnerability when processed by ImageMagick. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 7.8
debian
около 4 лет назад

A flaw was found in ImageMagick where it did not properly sanitize cer ...

CVSS3: 7.8
fstec
больше 4 лет назад

Уязвимость консольного графического редактора ImageMagick, связанная с использованием памяти после её освобождения, позволяющая нарушителю оказать влияние на целостность, доступность и конфиденциальность защищаемой информации

EPSS

Процентиль: 54%
0.00312
Низкий

Дефекты

CWE-416