PT-2017-3866 · Graphicsmagick+2 · Graphicsmagick+2
Hackyzh
·
Publicado
2017-10-22
·
Atualizado
2020-01-08
·
CVE-2017-15930
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GraphicsMagick version 1.3.26
Description
The issue is related to a Null Pointer Dereference in the
ReadOneJNGImage function, located in coders/png.c, which can occur while transferring JPEG scanlines. This is connected to a PixelPacket pointer. Exploitation of this issue may allow a remote attacker to execute arbitrary code.Recommendations
For GraphicsMagick version 1.3.26, consider disabling the
ReadOneJNGImage function as a temporary workaround until a patch is available. Restrict access to the coders/png.c module to minimize the risk of exploitation. Avoid using the PixelPacket pointer in the affected function until the issue is resolved.Correção
NULL Pointer Dereference
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Graphicsmagick
Suse
Ubuntu