Описание
ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metadata before pixel cache memory allocation. Attackers can trigger memory and disk allocation failures to cause a heap-buffer-overflow read affecting any writer calling GetPixelIndex.
A heap-buffer-overflow read in ImageMagick's OpenPixelCache occurs when image channel metadata updates before memory allocation. Attackers can trigger this via memory and disk allocation failures to disclose sensitive information.
Отчет
This vulnerability in ImageMagick is rated as Low impact. A heap-buffer-overflow read can occur in the GetPixelIndex function if OpenPixelCache updates image channel metadata before memory allocation, and both memory and disk allocation subsequently fail. Exploitation requires an attacker to trigger these specific resource exhaustion conditions, which limits the practical attack surface and reduces the overall risk of information disclosure on standard Red Hat deployments.
Меры по смягчению последствий
Isolate ImageMagick tasks by running them inside unprivileged containers (such as Podman) with strict SELinux confinement. Alternatively, sanitize untrusted files using an intermediate script to strip complex metadata before passing them to ImageMagick.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | ImageMagick | Out of support scope | ||
| Red Hat Enterprise Linux 7 | ImageMagick | Out of support scope |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
3.3 Low
CVSS3
Связанные уязвимости
ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metadata before pixel cache memory allocation. Attackers can trigger memory and disk allocation failures to cause a heap-buffer-overflow read affecting any writer calling GetPixelIndex.
ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metadata before pixel cache memory allocation. Attackers can trigger memory and disk allocation failures to cause a heap-buffer-overflow read affecting any writer calling GetPixelIndex.
ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulne ...
3.3 Low
CVSS3