Описание
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling rows.
A heap-based buffer overflow was discovered in ImageMagick in the way it parses images when using the evaluate-sequence option. Applications compiled against ImageMagick libraries that accept untrustworthy images and use the evaluate-sequence option or function EvaluateImages may be vulnerable to this flaw. An attacker could abuse this flaw by providing a specially crafted image to make the application crash or potentially execute code.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | ImageMagick | Out of support scope | ||
Red Hat Enterprise Linux 6 | ImageMagick | Out of support scope | ||
Red Hat Enterprise Linux 7 | autotrace | Fixed | RHSA-2020:1180 | 31.03.2020 |
Red Hat Enterprise Linux 7 | emacs | Fixed | RHSA-2020:1180 | 31.03.2020 |
Red Hat Enterprise Linux 7 | ImageMagick | Fixed | RHSA-2020:1180 | 31.03.2020 |
Red Hat Enterprise Linux 7 | inkscape | Fixed | RHSA-2020:1180 | 31.03.2020 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.3 High
CVSS3
Связанные уязвимости
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling rows.
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling rows.
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCor ...
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling rows.
Уязвимость функции EvaluateImages консольного графического редактора ImageMagick, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
7.3 High
CVSS3