Описание
A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm.c file. This vulnerability is triggered when an attacker passes a specially crafted DICOM image file to ImageMagick for conversion, potentially leading to information disclosure and a denial of service.
Релиз | Статус | Примечание |
---|---|---|
bionic | not-affected | code-not-present |
devel | released | 8:6.9.11.60+dfsg-1.3ubuntu1 |
esm-apps/focal | not-affected | code-not-present |
esm-apps/jammy | released | 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+esm1 |
esm-apps/noble | released | 8:6.9.11.60+dfsg-1.3ubuntu1 |
esm-infra-legacy/trusty | not-affected | code-not-present |
esm-infra/bionic | not-affected | code-not-present |
esm-infra/xenial | not-affected | code-not-present |
focal | not-affected | code-not-present |
impish | ignored | end of life |
Показывать по
EPSS
5.8 Medium
CVSS2
7.1 High
CVSS3
Связанные уязвимости
A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm.c file. This vulnerability is triggered when an attacker passes a specially crafted DICOM image file to ImageMagick for conversion, potentially leading to information disclosure and a denial of service.
A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm.c file. This vulnerability is triggered when an attacker passes a specially crafted DICOM image file to ImageMagick for conversion, potentially leading to information disclosure and a denial of service.
A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInf ...
A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm.c file. This vulnerability is triggered when an attacker passes a specially crafted DICOM image file to ImageMagick for conversion, potentially leading to information disclosure and a denial of service.
Уязвимость функции RelinquishDCMInfo() компонента dcm.c консольного графического редактора ImageMagick, позволяющая нарушителю получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании
EPSS
5.8 Medium
CVSS2
7.1 High
CVSS3