Логотип exploitDog
bind:"CVE-2020-25664"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2020-25664"

Количество 11

Количество 11

ubuntu логотип

CVE-2020-25664

около 5 лет назад

In WriteOnePNGImage() of the PNG coder at coders/png.c, an improper call to AcquireVirtualMemory() and memset() allows for an out-of-bounds write later when PopShortPixel() from MagickCore/quantum-private.h is called. The patch fixes the calls by adding 256 to rowbytes. An attacker who is able to supply a specially crafted image could affect availability with a low impact to data integrity. This flaw affects ImageMagick versions prior to 6.9.10-68 and 7.0.8-68.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2020-25664

больше 6 лет назад

In WriteOnePNGImage() of the PNG coder at coders/png.c, an improper call to AcquireVirtualMemory() and memset() allows for an out-of-bounds write later when PopShortPixel() from MagickCore/quantum-private.h is called. The patch fixes the calls by adding 256 to rowbytes. An attacker who is able to supply a specially crafted image could affect availability with a low impact to data integrity. This flaw affects ImageMagick versions prior to 6.9.10-68 and 7.0.8-68.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2020-25664

около 5 лет назад

In WriteOnePNGImage() of the PNG coder at coders/png.c, an improper call to AcquireVirtualMemory() and memset() allows for an out-of-bounds write later when PopShortPixel() from MagickCore/quantum-private.h is called. The patch fixes the calls by adding 256 to rowbytes. An attacker who is able to supply a specially crafted image could affect availability with a low impact to data integrity. This flaw affects ImageMagick versions prior to 6.9.10-68 and 7.0.8-68.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2020-25664

около 5 лет назад

In WriteOnePNGImage() of the PNG coder at coders/png.c, an improper ca ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-c5hg-hx4v-7q6w

больше 3 лет назад

In WriteOnePNGImage() of the PNG coder at coders/png.c, an improper call to AcquireVirtualMemory() and memset() allows for an out-of-bounds write later when PopShortPixel() from MagickCore/quantum-private.h is called. The patch fixes the calls by adding 256 to rowbytes. An attacker who is able to supply a specially crafted image could affect availability with a low impact to data integrity. This flaw affects ImageMagick versions prior to 6.9.10-68 and 7.0.8-68.

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:14598-1

около 5 лет назад

Security update for ImageMagick

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:0199-1

около 5 лет назад

Security update for ImageMagick

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:0153-1

около 5 лет назад

Security update for ImageMagick

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:0148-1

около 5 лет назад

Security update for ImageMagick

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:0136-1

около 5 лет назад

Security update for ImageMagick

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:0156-1

около 5 лет назад

Security update for ImageMagick

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-25664

In WriteOnePNGImage() of the PNG coder at coders/png.c, an improper call to AcquireVirtualMemory() and memset() allows for an out-of-bounds write later when PopShortPixel() from MagickCore/quantum-private.h is called. The patch fixes the calls by adding 256 to rowbytes. An attacker who is able to supply a specially crafted image could affect availability with a low impact to data integrity. This flaw affects ImageMagick versions prior to 6.9.10-68 and 7.0.8-68.

CVSS3: 6.1
0%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-25664

In WriteOnePNGImage() of the PNG coder at coders/png.c, an improper call to AcquireVirtualMemory() and memset() allows for an out-of-bounds write later when PopShortPixel() from MagickCore/quantum-private.h is called. The patch fixes the calls by adding 256 to rowbytes. An attacker who is able to supply a specially crafted image could affect availability with a low impact to data integrity. This flaw affects ImageMagick versions prior to 6.9.10-68 and 7.0.8-68.

CVSS3: 6.1
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2020-25664

In WriteOnePNGImage() of the PNG coder at coders/png.c, an improper call to AcquireVirtualMemory() and memset() allows for an out-of-bounds write later when PopShortPixel() from MagickCore/quantum-private.h is called. The patch fixes the calls by adding 256 to rowbytes. An attacker who is able to supply a specially crafted image could affect availability with a low impact to data integrity. This flaw affects ImageMagick versions prior to 6.9.10-68 and 7.0.8-68.

CVSS3: 6.1
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-25664

In WriteOnePNGImage() of the PNG coder at coders/png.c, an improper ca ...

CVSS3: 6.1
0%
Низкий
около 5 лет назад
github логотип
GHSA-c5hg-hx4v-7q6w

In WriteOnePNGImage() of the PNG coder at coders/png.c, an improper call to AcquireVirtualMemory() and memset() allows for an out-of-bounds write later when PopShortPixel() from MagickCore/quantum-private.h is called. The patch fixes the calls by adding 256 to rowbytes. An attacker who is able to supply a specially crafted image could affect availability with a low impact to data integrity. This flaw affects ImageMagick versions prior to 6.9.10-68 and 7.0.8-68.

0%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2021:14598-1

Security update for ImageMagick

около 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:0199-1

Security update for ImageMagick

около 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:0153-1

Security update for ImageMagick

около 5 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0148-1

Security update for ImageMagick

около 5 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0136-1

Security update for ImageMagick

около 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:0156-1

Security update for ImageMagick

около 5 лет назад

Уязвимостей на страницу