Описание
ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerability in ConnectedComponentsImage() when processing connected-components artifacts with invalid indices. Attackers can trigger access violations by specifying malformed connected-components definitions via CLI, causing denial of service or potential code execution.
An out-of-bounds access vulnerability exists in ImageMagick's ConnectedComponentsImage() function. By passing malformed connected-components definitions through the CLI, an attacker can cause a denial of service or potentially execute arbitrary code.
Отчет
An out-of-bounds access flaw exists in ImageMagick when handling malformed connected-components artifacts. Exploitation requires local user interaction via the CLI and can result in a denial of service or arbitrary code execution.
Меры по смягчению последствий
Prevent the injection of malformed -connected-components flags by strictly sanitizing all user-supplied CLI input in backend applications. Additionally, if automated ImageMagick processing is not required, restrict execution permissions on the binaries to trusted administrative groups.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | ImageMagick | Out of support scope | ||
| Red Hat Enterprise Linux 7 | ImageMagick | Out of support scope |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
3.3 Low
CVSS3
Связанные уязвимости
ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerability in ConnectedComponentsImage() when processing connected-components artifacts with invalid indices. Attackers can trigger access violations by specifying malformed connected-components definitions via CLI, causing denial of service or potential code execution.
ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerability in ConnectedComponentsImage() when processing connected-components artifacts with invalid indices. Attackers can trigger access violations by specifying malformed connected-components definitions via CLI, causing denial of service or potential code execution.
ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerabi ...
3.3 Low
CVSS3