Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-16323

Опубликовано: 24 июл. 2018
Источник: redhat
CVSS3: 4.3
EPSS Средний

Описание

ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If the affected code is used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ImageMagickWill not fix
Red Hat Enterprise Linux 6ImageMagickWill not fix
Red Hat Enterprise Linux 7ImageMagickWill not fix
Red Hat Enterprise Linux 8ImageMagickWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-908
https://bugzilla.redhat.com/show_bug.cgi?id=1624964ImageMagick: Information leak in ReadXBMImage in coders/xbm.c

EPSS

Процентиль: 99%
0.49324
Средний

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 8 лет назад

ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If the affected code is used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data.

CVSS3: 6.5
nvd
почти 8 лет назад

ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If the affected code is used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data.

CVSS3: 6.5
debian
почти 8 лет назад

ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data ...

suse-cvrf
почти 8 лет назад

Security update for GraphicsMagick

CVSS3: 6.5
github
больше 4 лет назад

ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If the affected code is used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data.

EPSS

Процентиль: 99%
0.49324
Средний

4.3 Medium

CVSS3