Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wfj2-6fr9-gvjh

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

An exploitable out of bounds write exists in the handling of compressed TIFF images in ImageMagicks's convert utility. A crafted TIFF document can lead to an out of bounds write which in particular circumstances could be leveraged into remote code execution. The vulnerability can be triggered through any user controlled TIFF that is handled by this functionality.

An exploitable out of bounds write exists in the handling of compressed TIFF images in ImageMagicks's convert utility. A crafted TIFF document can lead to an out of bounds write which in particular circumstances could be leveraged into remote code execution. The vulnerability can be triggered through any user controlled TIFF that is handled by this functionality.

EPSS

Процентиль: 84%
0.02137
Низкий

7 High

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 9 лет назад

An exploitable out of bounds write exists in the handling of compressed TIFF images in ImageMagicks's convert utility. A crafted TIFF document can lead to an out of bounds write which in particular circumstances could be leveraged into remote code execution. The vulnerability can be triggered through any user controlled TIFF that is handled by this functionality.

CVSS3: 4.9
redhat
около 9 лет назад

An exploitable out of bounds write exists in the handling of compressed TIFF images in ImageMagicks's convert utility. A crafted TIFF document can lead to an out of bounds write which in particular circumstances could be leveraged into remote code execution. The vulnerability can be triggered through any user controlled TIFF that is handled by this functionality.

CVSS3: 7.8
nvd
около 9 лет назад

An exploitable out of bounds write exists in the handling of compressed TIFF images in ImageMagicks's convert utility. A crafted TIFF document can lead to an out of bounds write which in particular circumstances could be leveraged into remote code execution. The vulnerability can be triggered through any user controlled TIFF that is handled by this functionality.

CVSS3: 7.8
debian
около 9 лет назад

An exploitable out of bounds write exists in the handling of compresse ...

suse-cvrf
около 9 лет назад

Security update for ImageMagick

EPSS

Процентиль: 84%
0.02137
Низкий

7 High

CVSS3

Дефекты

CWE-787