Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vpgp-gjqv-364p

Опубликовано: 13 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.

A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.

EPSS

Процентиль: 4%
0.00022
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-122
CWE-787

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 лет назад

A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.

CVSS3: 5.5
redhat
около 2 лет назад

A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.

CVSS3: 5.5
nvd
около 2 лет назад

A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.

CVSS3: 5.5
debian
около 2 лет назад

A heap-based buffer overflow issue was discovered in ImageMagick's Imp ...

suse-cvrf
около 2 лет назад

Security update for ImageMagick

EPSS

Процентиль: 4%
0.00022
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-122
CWE-787