Описание
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check of a return value could lead to a heap buffer over-write in the MAT decoder on 32-bit systems. This issue has been patched in versions 6.9.13-48 and 7.1.2-24.
A flaw was found in ImageMagick. A missing check of a return value in the MAT decoder on 32-bit systems could lead to a heap buffer over-write. This vulnerability may allow an attacker to cause a denial of service.
Отчет
This Moderate impact flaw in ImageMagick could lead to a denial of service on 32-bit systems when processing a maliciously crafted MAT image file. The vulnerability arises from a missing return value check in the MAT decoder, which could result in a heap buffer over-write. Exploitation requires an attacker to provide a specially crafted image to a system running ImageMagick.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | ImageMagick | Out of support scope | ||
| Red Hat Enterprise Linux 7 | ImageMagick | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check of a return value could lead to a heap buffer over-write in the MAT decoder on 32-bit systems. This issue has been patched in versions 6.9.13-48 and 7.1.2-24.
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check of a return value could lead to a heap buffer over-write in the MAT decoder on 32-bit systems. This issue has been patched in versions 6.9.13-48 and 7.1.2-24.
ImageMagick is free and open-source software used for editing and mani ...
EPSS
5.9 Medium
CVSS3