Описание
ImageMagick before 7.1.2-19 contains an off-by-one error in morphology validation allowing out-of-bounds heap buffer reads. Attackers can trigger heap buffer overflow by providing incorrect morphology parameters causing single pixel memory access violations.
A flaw was found in ImageMagick. An attacker can exploit an off-by-one error in the morphology validation by providing incorrect morphology parameters. This can lead to out-of-bounds heap buffer reads and heap buffer overflow, potentially causing memory access violations.
Отчет
This flaw in ImageMagick is rated as Low impact. An attacker can trigger a memory access violation by submitting a maliciously crafted image. Red Hat has rated this low as there is no impact to the confidentiality of the data and availability is low as denial-of-service is strictly localized to the process handling that specific file.
Меры по смягчению последствий
To reduce exposure, avoid processing untrusted image files with ImageMagick, particularly those that may contain malformed morphology parameters. If processing untrusted content is necessary, consider implementing sandboxing mechanisms to isolate ImageMagick operations and limit the potential blast radius of any successful exploitation.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | ImageMagick | Out of support scope | ||
| Red Hat Enterprise Linux 7 | ImageMagick | Out of support scope |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
3.3 Low
CVSS3
Связанные уязвимости
ImageMagick before 7.1.2-19 contains an off-by-one error in morphology validation allowing out-of-bounds heap buffer reads. Attackers can trigger heap buffer overflow by providing incorrect morphology parameters causing single pixel memory access violations.
ImageMagick before 7.1.2-19 contains an off-by-one error in morphology validation allowing out-of-bounds heap buffer reads. Attackers can trigger heap buffer overflow by providing incorrect morphology parameters causing single pixel memory access violations.
ImageMagick before 7.1.2-19 contains an off-by-one error in morphology ...
EPSS
3.3 Low
CVSS3