Описание
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when using LZMA compression in the MIFF encoder an out of bounds write can occur due to a missing check. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.
A flaw was found in ImageMagick. When processing an image with LZMA compression in the MIFF encoder, a missing check can lead to an out-of-bounds write. This vulnerability could allow an attacker to cause a denial of service (DoS) by providing a specially crafted image file, leading to application instability or crashes.
Отчет
This Moderate impact flaw in ImageMagick allows an out-of-bounds write when processing specially crafted image files using LZMA compression within the MIFF encoder. While requiring user interaction to process a malicious image, this vulnerability could lead to a denial of service, causing application instability or crashes in Red Hat products that utilize ImageMagick for image manipulation.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | ImageMagick | Out of support scope | ||
| Red Hat Enterprise Linux 7 | ImageMagick | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when using LZMA compression in the MIFF encoder an out of bounds write can occur due to a missing check. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when using LZMA compression in the MIFF encoder an out of bounds write can occur due to a missing check. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.
ImageMagick is free and open-source software used for editing and mani ...
ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compression
Уязвимость кодировщика MIFF консольного графического редактора ImageMagick, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
5.5 Medium
CVSS3