PT-2019-2862 · Imagemagick+1 · Imagemagick+1
Suhwansong
·
Published
2019-06-21
·
Updated
2023-03-02
·
CVE-2019-13299
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ImageMagick versions 7.0.8-50
Description
The issue is related to a heap-based buffer over-read in the GetPixelChannel function, located in MagickCore/pixel-accessor.h. This can be exploited by a remote attacker using a specially crafted image, potentially leading to a denial of service or disclosure of protected information.
Recommendations
For ImageMagick version 7.0.8-50, consider disabling the GetPixelChannel function as a temporary workaround until a patch is available. Restrict access to the pixel-accessor.h module to minimize the risk of exploitation. Avoid using the GetPixelChannel function in the affected ImageMagick version until the issue is resolved.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Imagemagick
Suse