Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Juzhi Lu

Pesquisador deNSFOCUS Security Team
#21780de 53,640
11CVSS total
Vulnerabilidades · 2
Média
2
PT-2023-24900
5.5
2023-06-16
Unknown · Imagemagick · CVE-2023-34474
**Name of the Vulnerable Software and Affected Versions** ImageMagick (affected versions not specified) **Description** A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A local attacker could trick the user into opening a specially crafted file, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2023-8783
5.5
2023-06-16
Unknown · Imagemagick · CVE-2023-34475
**Name of the Vulnerable Software and Affected Versions** ImageMagick (affected versions not specified) **Description** A heap use after free issue was discovered in ImageMagick's `ReplaceXmpValue()` function in MagickCore/profile.c. This issue can be exploited by an attacker who tricks a user into opening a specially crafted file, triggering a heap-use-after-free write error. This error can cause an application to crash, resulting in a denial of service. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.