Описание
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of a too large shift for 64-bit type ssize_t. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.9-0.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 8:6.9.7.4+dfsg-16ubuntu6.11 |
| devel | not-affected | 8:6.9.11.60+dfsg-1ubuntu1 |
| esm-apps/focal | released | 8:6.9.10.23+dfsg-2.1ubuntu11.4 |
| esm-apps/jammy | not-affected | 8:6.9.11.60+dfsg-1ubuntu1 |
| esm-apps/noble | not-affected | 8:6.9.11.60+dfsg-1ubuntu1 |
| esm-infra-legacy/trusty | released | 8:6.7.7.10-6ubuntu3.13+esm11 |
| esm-infra/bionic | released | 8:6.9.7.4+dfsg-16ubuntu6.11 |
| esm-infra/xenial | released | 8:6.8.9.9-7ubuntu5.16+esm11 |
| focal | released | 8:6.9.10.23+dfsg-2.1ubuntu11.4 |
| groovy | released | 8:6.9.10.23+dfsg-2.1ubuntu13.3 |
Показывать по
4.3 Medium
CVSS2
3.3 Low
CVSS3
Связанные уязвимости
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of a too large shift for 64-bit type `ssize_t`. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.9-0.
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of a too large shift for 64-bit type `ssize_t`. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.9-0.
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker ...
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of a too large shift for 64-bit type `ssize_t`. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.9-0.
Уязвимость компонента MagickCore/statistic.c консольного графического редактора ImageMagick, связанная с целочисленным переполнением значения, позволяющая нарушителю вызвать отказ в обслуживании
4.3 Medium
CVSS2
3.3 Low
CVSS3