Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-5842

Опубликовано: 22 июн. 2016
Источник: redhat
CVSS3: 6.2
CVSS2: 4.3
EPSS Низкий

Описание

MagickCore/property.c in ImageMagick before 7.0.2-1 allows remote attackers to obtain sensitive memory information via vectors involving the q variable, which triggers an out-of-bounds read.

Отчет

This issue did not affect the versions of ImageMagick as shipped with Red Hat Enterprise Linux 5, 6, and 7.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ImageMagickNot affected
Red Hat Enterprise Linux 6ImageMagickNot affected
Red Hat Enterprise Linux 7ImageMagickNot affected
Red Hat OpenShift Enterprise 2ImageMagickNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1350461ImageMagick: Information leak in MagickCore/property.c

EPSS

Процентиль: 93%
0.06463
Низкий

6.2 Medium

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

MagickCore/property.c in ImageMagick before 7.0.2-1 allows remote attackers to obtain sensitive memory information via vectors involving the q variable, which triggers an out-of-bounds read.

CVSS3: 7.5
nvd
больше 9 лет назад

MagickCore/property.c in ImageMagick before 7.0.2-1 allows remote attackers to obtain sensitive memory information via vectors involving the q variable, which triggers an out-of-bounds read.

CVSS3: 7.5
debian
больше 9 лет назад

MagickCore/property.c in ImageMagick before 7.0.2-1 allows remote atta ...

CVSS3: 7.5
github
больше 4 лет назад

MagickCore/property.c in ImageMagick before 7.0.2-1 allows remote attackers to obtain sensitive memory information via vectors involving the q variable, which triggers an out-of-bounds read.

suse-cvrf
около 10 лет назад

Security update for ImageMagick

EPSS

Процентиль: 93%
0.06463
Низкий

6.2 Medium

CVSS3

4.3 Medium

CVSS2