Описание
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadXWDImage of coders/xwd.c, which allows attackers to cause a denial of service or information disclosure via a crafted image file.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 1.3.28-2ubuntu0.1 |
| cosmic | ignored | end of life |
| devel | not-affected | 1.4~hg15968-1 |
| disco | ignored | end of life |
| eoan | not-affected | 1.4~hg15968-1 |
| esm-apps/bionic | released | 1.3.28-2ubuntu0.1 |
| esm-apps/focal | not-affected | 1.4~hg15968-1 |
| esm-apps/jammy | not-affected | 1.4~hg15968-1 |
| esm-apps/noble | not-affected | 1.4~hg15968-1 |
| esm-apps/xenial | needed |
Показывать по
EPSS
5.8 Medium
CVSS2
8.1 High
CVSS3
Связанные уязвимости
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadXWDImage of coders/xwd.c, which allows attackers to cause a denial of service or information disclosure via a crafted image file.
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buff ...
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadXWDImage of coders/xwd.c, which allows attackers to cause a denial of service or information disclosure via a crafted image file.
Уязвимость функции ReadXWDImage графического редактора GraphicsMagick, связанная с чтением за границами буфера в памяти, позволяющая нарушителю получить несанкционированный доступ к информации и нарушить ее целостность и доступность
EPSS
5.8 Medium
CVSS2
8.1 High
CVSS3