PT-2018-3701 · Imagemagick+5 · Imagemagick+5

Riccardo Schirone

·

Published

2018-03-15

·

Updated

2024-09-04

·

CVE-2019-10131

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 7.0.7-28
Description The issue is related to an off-by-one read vulnerability in the formatIPTCfromBuffer function in coders/meta.c. This vulnerability allows an attacker to read beyond the end of the buffer or crash the program, potentially leading to unauthorized access to confidential data and denial of service.
Recommendations For versions prior to 7.0.7-28, update to version 7.0.7-28 or later to resolve the issue. As a temporary workaround, consider restricting access to the formatIPTCfromBuffer function in coders/meta.c to minimize the risk of exploitation.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1520
BDU:2021-03441
CESA-2020_1180
CVE-2019-10131
DLA-2333-1
OPENSUSE-SU-2019_1427-1
OPENSUSE-SU-2019_1683-1
RHSA-2020:1180
RHSA-2020_1180
SUSE-SU-2019:1712-1
USN-4034-1
USN-6985-1

Affected Products

Alt Linux
Centos
Imagemagick
Red Hat
Suse
Ubuntu