Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3962

Опубликовано: 15 нояб. 2021
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

A flaw was found in ImageMagick where it did not properly sanitize certain input before using it to invoke convert processes. This flaw allows an attacker to create a specially crafted image that leads to a use-after-free vulnerability when processed by ImageMagick. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickNot affected
Red Hat Enterprise Linux 7ImageMagickNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2023196ImageMagick: heap-use-after-free in at dcm.c RelinquishDCMMemory

EPSS

Процентиль: 54%
0.00312
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 4 лет назад

A flaw was found in ImageMagick where it did not properly sanitize certain input before using it to invoke convert processes. This flaw allows an attacker to create a specially crafted image that leads to a use-after-free vulnerability when processed by ImageMagick. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 7.8
nvd
около 4 лет назад

A flaw was found in ImageMagick where it did not properly sanitize certain input before using it to invoke convert processes. This flaw allows an attacker to create a specially crafted image that leads to a use-after-free vulnerability when processed by ImageMagick. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 7.8
debian
около 4 лет назад

A flaw was found in ImageMagick where it did not properly sanitize cer ...

github
больше 3 лет назад

A flaw was found in ImageMagick 7.1.0-14 where it did not properly sanitize certain input before using it to invoke convert processes. This flaw allows an attacker to create a specially crafted image that leads to a use-after-free vulnerability when processed by ImageMagick. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 7.8
fstec
больше 4 лет назад

Уязвимость консольного графического редактора ImageMagick, связанная с использованием памяти после её освобождения, позволяющая нарушителю оказать влияние на целостность, доступность и конфиденциальность защищаемой информации

EPSS

Процентиль: 54%
0.00312
Низкий

5.3 Medium

CVSS3