PT-2016-6710 · Imagemagick+3 · Imagemagick+3
Ibrahim M. El-Sayed
·
Publicado
2016-06-27
·
Atualizado
2021-04-28
·
CVE-2016-5842
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ImageMagick versions prior to 7.0.2-1
Description
The issue allows remote attackers to obtain sensitive memory information via vectors involving the
q variable, which triggers an out-of-bounds read. This occurs in the MagickCore/property.c file.Recommendations
For versions prior to 7.0.2-1, update to version 7.0.2-1 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive memory information to minimize the risk of exploitation.
Exploit
Correção
Out of bounds Read
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Imagemagick
Suse
Ubuntu