Описание
ImageMagick 7.0.7-26 Q16 has excessive iteration in the DecodeLabImage and EncodeLabImage functions (coders/tiff.c), which results in a hang (tens of minutes) with a tiny PoC file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tiff file.
Релиз | Статус | Примечание |
---|---|---|
artful | released | 8:6.9.7.4+dfsg-16ubuntu2.2 |
bionic | released | 8:6.9.7.4+dfsg-16ubuntu6.2 |
devel | released | 8:6.9.7.4+dfsg-16ubuntu8 |
esm-infra-legacy/trusty | not-affected | code not present |
esm-infra/bionic | not-affected | 8:6.9.7.4+dfsg-16ubuntu6.2 |
esm-infra/xenial | not-affected | 8:6.8.9.9-7ubuntu5.11 |
precise/esm | DNE | |
trusty | not-affected | code not present |
trusty/esm | not-affected | code not present |
upstream | needs-triage |
Показывать по
EPSS
4.3 Medium
CVSS2
6.5 Medium
CVSS3
Связанные уязвимости
ImageMagick 7.0.7-26 Q16 has excessive iteration in the DecodeLabImage and EncodeLabImage functions (coders/tiff.c), which results in a hang (tens of minutes) with a tiny PoC file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tiff file.
ImageMagick 7.0.7-26 Q16 has excessive iteration in the DecodeLabImage and EncodeLabImage functions (coders/tiff.c), which results in a hang (tens of minutes) with a tiny PoC file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tiff file.
ImageMagick 7.0.7-26 Q16 has excessive iteration in the DecodeLabImage ...
ImageMagick 7.0.7-26 Q16 has excessive iteration in the DecodeLabImage and EncodeLabImage functions (coders/tiff.c), which results in a hang (tens of minutes) with a tiny PoC file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tiff file.
Уязвимость функций DecodeLabImage и EncodeLabImage компонента coders/tiff.c консольного графического редактора ImageMagick, связанная с чрезмерным итерированием, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
4.3 Medium
CVSS2
6.5 Medium
CVSS3