Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-0284

Опубликовано: 18 янв. 2022
Источник: redhat
CVSS3: 5.1
EPSS Низкий

Описание

A heap-based-buffer-over-read flaw was found in ImageMagick's GetPixelAlpha() function of 'pixel-accessor.h'. This vulnerability is triggered when an attacker passes a specially crafted Tagged Image File Format (TIFF) image to convert it into a PICON file format. This issue can potentially lead to a denial of service and information disclosure.

Отчет

The versions of ImageMagick shipped with Red Hat Enterprise Linux 6, 7 are ImageMagick v6.9.10 and lower. These contain a different code-base compared to upstream and the vulnerable code is not present in our code-base.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickNot affected
Red Hat Enterprise Linux 7ImageMagickNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2045943ImageMagick: Heap buffer overread in GetPixelAlpha() declared in MagickCore/pixel-accessor.h

EPSS

Процентиль: 11%
0.00038
Низкий

5.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 3 лет назад

A heap-based-buffer-over-read flaw was found in ImageMagick's GetPixelAlpha() function of 'pixel-accessor.h'. This vulnerability is triggered when an attacker passes a specially crafted Tagged Image File Format (TIFF) image to convert it into a PICON file format. This issue can potentially lead to a denial of service and information disclosure.

CVSS3: 7.1
nvd
больше 3 лет назад

A heap-based-buffer-over-read flaw was found in ImageMagick's GetPixelAlpha() function of 'pixel-accessor.h'. This vulnerability is triggered when an attacker passes a specially crafted Tagged Image File Format (TIFF) image to convert it into a PICON file format. This issue can potentially lead to a denial of service and information disclosure.

CVSS3: 7.1
debian
больше 3 лет назад

A heap-based-buffer-over-read flaw was found in ImageMagick's GetPixel ...

suse-cvrf
почти 4 года назад

Security update for ImageMagick

suse-cvrf
почти 4 года назад

Security update for ImageMagick

EPSS

Процентиль: 11%
0.00038
Низкий

5.1 Medium

CVSS3