Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-3428

Опубликовано: 04 окт. 2023
Источник: nvd
CVSS3: 6.2
CVSS3: 5.5
EPSS Низкий

Описание

A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local attacker to trick the user into opening a specially crafted file, resulting in an application crash and denial of service.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Версия до 7.1.1-19 (исключая)
Конфигурация 2

Одно из

cpe:2.3:a:fedoraproject:extra_packages_for_enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:-:*:*:*:*:*:*:*

EPSS

Процентиль: 5%
0.00023
Низкий

6.2 Medium

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-122
CWE-787

Связанные уязвимости

CVSS3: 6.2
ubuntu
больше 1 года назад

A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local attacker to trick the user into opening a specially crafted file, resulting in an application crash and denial of service.

CVSS3: 6.2
redhat
почти 2 года назад

A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local attacker to trick the user into opening a specially crafted file, resulting in an application crash and denial of service.

CVSS3: 6.2
debian
больше 1 года назад

A heap-based buffer overflow vulnerability was found in coders/tiff.c ...

CVSS3: 5.5
redos
больше 1 года назад

Уязвимости ImageMagick

CVSS3: 5.5
redos
больше 1 года назад

Уязвимости ImageMagick

EPSS

Процентиль: 5%
0.00023
Низкий

6.2 Medium

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-122
CWE-787