PT-2019-2941 · Imagemagick+4 · Imagemagick+4

Suhwansong

·

Publicado

2019-07-05

·

Atualizado

2024-10-03

·

CVE-2019-13304

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ImageMagick versions 7.0.8-50
Description The issue is related to a buffer overflow in the WritePNMImage function in the coders/pnm.c file of the ImageMagick console graphic editor. This can be exploited by a remote attacker using a specially crafted image, potentially leading to a denial of service or the execution of arbitrary code.
Recommendations For ImageMagick version 7.0.8-50, consider disabling the WritePNMImage function in coders/pnm.c as a temporary workaround until a patch is available. Restrict the use of the ImageMagick console graphic editor to minimize the risk of exploitation.

Exploit

Correção

Memory Corruption

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-02916
CESA-2020_1180
CVE-2019-13304
DLA-1888-1
DSA-4712-1
DSA-4715-1
OPENSUSE-SU-2019:1983-1
OPENSUSE-SU-2019_1983-1
RHSA-2020:1180
RHSA-2020_1180
SUSE-SU-2019:2106-1
USN-4192-1
USN-7053-1

Produtos afetados

Centos
Imagemagick
Red Hat
Suse
Ubuntu