Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-16323

Опубликовано: 24 июл. 2018
Источник: redhat
CVSS3: 4.3

Описание

ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If the affected code is used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ImageMagickWill not fix
Red Hat Enterprise Linux 6ImageMagickWill not fix
Red Hat Enterprise Linux 7ImageMagickWill not fix
Red Hat Enterprise Linux 8ImageMagickWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-665->CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1624964ImageMagick: Information leak in ReadXBMImage in coders/xbm.c

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If the affected code is used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data.

CVSS3: 6.5
nvd
больше 7 лет назад

ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If the affected code is used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data.

CVSS3: 6.5
debian
больше 7 лет назад

ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data ...

suse-cvrf
больше 7 лет назад

Security update for GraphicsMagick

CVSS3: 6.5
github
больше 3 лет назад

ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If the affected code is used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data.

4.3 Medium

CVSS3