PT-2019-2862 · Imagemagick+1 · Imagemagick+1

Suhwansong

·

Publicado

2019-06-21

·

Atualizado

2023-03-02

·

CVE-2019-13299

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ImageMagick versions 7.0.8-50
Description The issue is related to a heap-based buffer over-read in the GetPixelChannel function, located in MagickCore/pixel-accessor.h. This can be exploited by a remote attacker using a specially crafted image, potentially leading to a denial of service or disclosure of protected information.
Recommendations For ImageMagick version 7.0.8-50, consider disabling the GetPixelChannel function as a temporary workaround until a patch is available. Restrict access to the pixel-accessor.h module to minimize the risk of exploitation. Avoid using the GetPixelChannel function in the affected ImageMagick version until the issue is resolved.

Exploit

Correção

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-02830
CVE-2019-13299
OPENSUSE-SU-2019:1983-1
OPENSUSE-SU-2019_1983-1
SUSE-SU-2019:2106-1

Produtos afetados

Imagemagick
Suse