Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-18025

Опубликовано: 05 окт. 2018
Источник: redhat
CVSS3: 3.3

Описание

In ImageMagick 7.0.8-13 Q16, there is a heap-based buffer over-read in the EncodeImage function of coders/pict.c, which allows attackers to cause a denial of service via a crafted SVG image file.

Отчет

This issue did not affect the versions of ImageMagick as shipped with Red Hat Enterprise Linux 5, 6, and 7.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ImageMagickNot affected
Red Hat Enterprise Linux 6ImageMagickNot affected
Red Hat Enterprise Linux 7ImageMagickNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1637191ImageMagick: heap-based buffer over-read in the EncodeImage function of coders/pict.c

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 8 лет назад

In ImageMagick 7.0.8-13 Q16, there is a heap-based buffer over-read in the EncodeImage function of coders/pict.c, which allows attackers to cause a denial of service via a crafted SVG image file.

CVSS3: 6.5
nvd
почти 8 лет назад

In ImageMagick 7.0.8-13 Q16, there is a heap-based buffer over-read in the EncodeImage function of coders/pict.c, which allows attackers to cause a denial of service via a crafted SVG image file.

CVSS3: 6.5
debian
почти 8 лет назад

In ImageMagick 7.0.8-13 Q16, there is a heap-based buffer over-read in ...

CVSS3: 6.5
github
больше 4 лет назад

In ImageMagick 7.0.8-13 Q16, there is a heap-based buffer over-read in the EncodeImage function of coders/pict.c, which allows attackers to cause a denial of service via a crafted SVG image file.

CVSS3: 6.5
fstec
почти 8 лет назад

Уязвимость функции EncodeImage компонента coders/pict.c консольного графического редактора ImageMagick, связанная с чтением за допустимыми границами буфера данных, позволяющая нарушителю вызвать отказ в обслуживании

3.3 Low

CVSS3