Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-16546

Опубликовано: 04 нояб. 2017
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colormap index in a WPG palette, which allows remote attackers to cause a denial of service (use of uninitialized data or invalid memory allocation) or possibly have unspecified other impact via a malformed WPG file.

Отчет

Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ImageMagickWill not fix
Red Hat Enterprise Linux 6ImageMagickWill not fix
Red Hat Enterprise Linux 7ImageMagickWill not fix

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1513940ImageMagick: Invalid memory allocation in the ReadWPGImage function

EPSS

Процентиль: 69%
0.00594
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 8 лет назад

The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colormap index in a WPG palette, which allows remote attackers to cause a denial of service (use of uninitialized data or invalid memory allocation) or possibly have unspecified other impact via a malformed WPG file.

CVSS3: 8.8
nvd
больше 8 лет назад

The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colormap index in a WPG palette, which allows remote attackers to cause a denial of service (use of uninitialized data or invalid memory allocation) or possibly have unspecified other impact via a malformed WPG file.

CVSS3: 8.8
debian
больше 8 лет назад

The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does ...

CVSS3: 8.8
github
больше 3 лет назад

The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colormap index in a WPG palette, which allows remote attackers to cause a denial of service (use of uninitialized data or invalid memory allocation) or possibly have unspecified other impact via a malformed WPG file.

suse-cvrf
около 8 лет назад

Security update for GraphicsMagick

EPSS

Процентиль: 69%
0.00594
Низкий

3.3 Low

CVSS3