Описание
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a signed integer overflow vulnerability in ImageMagick's SIXEL decoder allows an attacker to trigger memory corruption and denial of service when processing a maliciously crafted SIXEL image file. The vulnerability occurs during buffer reallocation operations where pointer arithmetic using signed 32-bit integers overflows. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 8:7.1.2.15+dfsg1-1 |
| esm-apps/focal | released | 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm9 |
| esm-apps/jammy | released | 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm9 |
| esm-apps/noble | released | 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm8 |
| esm-apps/resolute | not-affected | 8:7.1.2.15+dfsg1-1 |
| esm-infra-legacy/trusty | not-affected | code not present |
| esm-infra-legacy/xenial | released | 8:6.8.9.9-7ubuntu5.16+esm19 |
| esm-infra/bionic | released | 8:6.9.7.4+dfsg-16ubuntu6.15+esm11 |
| esm-infra/xenial | released | 8:6.8.9.9-7ubuntu5.16+esm19 |
| jammy | needed |
Показывать по
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a signed integer overflow vulnerability in ImageMagick's SIXEL decoder allows an attacker to trigger memory corruption and denial of service when processing a maliciously crafted SIXEL image file. The vulnerability occurs during buffer reallocation operations where pointer arithmetic using signed 32-bit integers overflows. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a signed integer overflow vulnerability in ImageMagick's SIXEL decoder allows an attacker to trigger memory corruption and denial of service when processing a maliciously crafted SIXEL image file. The vulnerability occurs during buffer reallocation operations where pointer arithmetic using signed 32-bit integers overflows. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
ImageMagick is free and open-source software used for editing and mani ...
ImageMagick Has Signed Integer Overflow in SIXEL Decoder, Leading to Memory Corruption
Уязвимость декодера SIXEL консольного графического редактора ImageMagick, позволяющая нарушителю вызвать повреждение памяти и отказ в обслуживании
EPSS
5.3 Medium
CVSS3