Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-20185

Опубликовано: 17 дек. 2018
Источник: ubuntu
Приоритет: medium
CVSS2: 2.6
CVSS3: 5.3

Описание

In GraphicsMagick 1.4 snapshot-20181209 Q8 on 32-bit platforms, there is a heap-based buffer over-read in the ReadBMPImage function of bmp.c, which allows attackers to cause a denial of service via a crafted bmp image file. This only affects GraphicsMagick installations with customized BMP limits.

РелизСтатусПримечание
bionic

released

1.3.28-2ubuntu0.1
cosmic

ignored

end of life
devel

not-affected

1.4~hg15873-1
disco

not-affected

1.4~hg15873-1
eoan

not-affected

1.4~hg15873-1
esm-apps/bionic

released

1.3.28-2ubuntu0.1
esm-apps/focal

not-affected

1.4~hg15873-1
esm-apps/jammy

not-affected

1.4~hg15873-1
esm-apps/noble

not-affected

1.4~hg15873-1
esm-apps/xenial

needed

Показывать по

2.6 Low

CVSS2

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
около 7 лет назад

In GraphicsMagick 1.4 snapshot-20181209 Q8 on 32-bit platforms, there is a heap-based buffer over-read in the ReadBMPImage function of bmp.c, which allows attackers to cause a denial of service via a crafted bmp image file. This only affects GraphicsMagick installations with customized BMP limits.

CVSS3: 5.3
debian
около 7 лет назад

In GraphicsMagick 1.4 snapshot-20181209 Q8 on 32-bit platforms, there ...

CVSS3: 5.3
github
больше 3 лет назад

In GraphicsMagick 1.4 snapshot-20181209 Q8 on 32-bit platforms, there is a heap-based buffer over-read in the ReadBMPImage function of bmp.c, which allows attackers to cause a denial of service via a crafted bmp image file. This only affects GraphicsMagick installations with customized BMP limits.

fstec
около 7 лет назад

Уязвимость функции ReadBMPImage графического редактора GraphicsMagick, связанная с чтение за границами буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании

suse-cvrf
около 7 лет назад

Security update for GraphicsMagick

2.6 Low

CVSS2

5.3 Medium

CVSS3