Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-0259

Опубликовано: 28 мар. 2012
Источник: redhat
CVSS2: 4.3

Описание

The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (crash) via a zero value in the component count of an EXIF XResolution tag in a JPEG file, which triggers an out-of-bounds read.

Отчет

Not vulnerable. This issue did not affect the versions of ImageMagick as shipped with Red Hat Enterprise Linux 6 as it did not backport the insufficient patch for CVE-2012-0259.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ImageMagickNot affected
Red Hat Enterprise Linux 6ImageMagickFixedRHSA-2012:054407.05.2012

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=807993ImageMagick: Out-of heap-based buffer read by processing crafted JPEG EXIF header tag value

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 13 лет назад

The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (crash) via a zero value in the component count of an EXIF XResolution tag in a JPEG file, which triggers an out-of-bounds read.

CVSS3: 6.5
nvd
около 13 лет назад

The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (crash) via a zero value in the component count of an EXIF XResolution tag in a JPEG file, which triggers an out-of-bounds read.

CVSS3: 6.5
debian
около 13 лет назад

The GetEXIFProperty function in magick/property.c in ImageMagick befor ...

CVSS3: 6.5
github
больше 3 лет назад

The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (crash) via a zero value in the component count of an EXIF XResolution tag in a JPEG file, which triggers an out-of-bounds read.

oracle-oval
больше 13 лет назад

ELSA-2012-0544: ImageMagick security update (MODERATE)

4.3 Medium

CVSS2