PT-2017-2998 · Imagemagick+1 · Imagemagick+1

Publicado

2017-09-13

·

Atualizado

2019-10-03

·

CVE-2017-15032

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ImageMagick version 7.0.7-2
Description The issue is related to a memory leak in the ReadYCBCRImage function, located in coders/ycbcr.c. This memory leak can be exploited by a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For ImageMagick version 7.0.7-2, consider applying a patch or updating to a newer version to fix the memory leak in the ReadYCBCRImage function. As a temporary workaround, restrict the use of the ReadYCBCRImage function in coders/ycbcr.c to minimize the risk of exploitation.

Exploit

Correção

Missing Release of Resource after Effective Lifetime

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02350
CVE-2017-15032
USN-3681-1

Produtos afetados

Imagemagick
Ubuntu