Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-11470

Опубликовано: 23 апр. 2019
Источник: nvd
CVSS3: 6.5
CVSS2: 7.1
EPSS Низкий

Описание

The cineon parsing component in ImageMagick 7.0.8-26 Q16 allows attackers to cause a denial-of-service (uncontrolled resource consumption) by crafting a Cineon image with an incorrect claimed image size. This occurs because ReadCINImage in coders/cin.c lacks a check for insufficient image data in a file.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:imagemagick:imagemagick:7.0.8-26:q16:*:*:*:*:*:*

EPSS

Процентиль: 72%
0.0074
Низкий

6.5 Medium

CVSS3

7.1 High

CVSS2

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 6 лет назад

The cineon parsing component in ImageMagick 7.0.8-26 Q16 allows attackers to cause a denial-of-service (uncontrolled resource consumption) by crafting a Cineon image with an incorrect claimed image size. This occurs because ReadCINImage in coders/cin.c lacks a check for insufficient image data in a file.

CVSS3: 5.3
redhat
больше 6 лет назад

The cineon parsing component in ImageMagick 7.0.8-26 Q16 allows attackers to cause a denial-of-service (uncontrolled resource consumption) by crafting a Cineon image with an incorrect claimed image size. This occurs because ReadCINImage in coders/cin.c lacks a check for insufficient image data in a file.

CVSS3: 6.5
debian
около 6 лет назад

The cineon parsing component in ImageMagick 7.0.8-26 Q16 allows attack ...

github
около 3 лет назад

The cineon parsing component in ImageMagick 7.0.8-26 Q16 allows attackers to cause a denial-of-service (uncontrolled resource consumption) by crafting a Cineon image with an incorrect claimed image size. This occurs because ReadCINImage in coders/cin.c lacks a check for insufficient image data in a file.

CVSS3: 6.5
fstec
около 6 лет назад

Уязвимость функции ReadCINImage (coders/cin.c) компонента синтаксического анализа Cineon программы для чтения и редактирования графических файлов ImageMagick, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 72%
0.0074
Низкий

6.5 Medium

CVSS3

7.1 High

CVSS2

Дефекты

CWE-400