Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rhcm-mpjw-m6hf

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm.c file. This vulnerability is triggered when an attacker passes a specially crafted DICOM image file to ImageMagick for conversion, potentially leading to information disclosure and a denial of service.

A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm.c file. This vulnerability is triggered when an attacker passes a specially crafted DICOM image file to ImageMagick for conversion, potentially leading to information disclosure and a denial of service.

EPSS

Процентиль: 24%
0.00077
Низкий

7.1 High

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 3 лет назад

A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm.c file. This vulnerability is triggered when an attacker passes a specially crafted DICOM image file to ImageMagick for conversion, potentially leading to information disclosure and a denial of service.

CVSS3: 6.1
redhat
больше 3 лет назад

A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm.c file. This vulnerability is triggered when an attacker passes a specially crafted DICOM image file to ImageMagick for conversion, potentially leading to information disclosure and a denial of service.

CVSS3: 7.1
nvd
около 3 лет назад

A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm.c file. This vulnerability is triggered when an attacker passes a specially crafted DICOM image file to ImageMagick for conversion, potentially leading to information disclosure and a denial of service.

CVSS3: 7.1
debian
около 3 лет назад

A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInf ...

CVSS3: 6.8
fstec
больше 3 лет назад

Уязвимость функции RelinquishDCMInfo() компонента dcm.c консольного графического редактора ImageMagick, позволяющая нарушителю получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании

EPSS

Процентиль: 24%
0.00077
Низкий

7.1 High

CVSS3

Дефекты

CWE-416