4.3
CVSSv2

CVE-2018-11251

Published: 18/05/2018 Updated: 03/10/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

In ImageMagick 7.0.7-23 Q16 x86_64 2018-01-24, there is a heap-based buffer over-read in ReadSUNImage in coders/sun.c, which allows malicious users to cause a denial of service (application crash in SetGrayscaleImage in MagickCore/quantize.c) via a crafted SUN image file.

Vulnerable Product Search on Vulmon Subscribe to Product

imagemagick imagemagick

imagemagick imagemagick 7.0.7-23

Vendor Advisories

Debian Bug report logs - #902728 CVE-2018-12600 Package: imagemagick; Maintainer for imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Source for imagemagick is src:imagemagick (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Fri, 29 Jun 2018 21:15:04 ...
Debian Bug report logs - #902727 CVE-2018-12599 Package: imagemagick; Maintainer for imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Source for imagemagick is src:imagemagick (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Fri, 29 Jun 2018 21:15:01 ...
Several security issues were fixed in ImageMagick ...
This update fixes several vulnerabilities in Imagemagick, a graphical software suite Various memory handling problems or incomplete input sanitising could result in denial of service or the execution of arbitrary code For the stable distribution (stretch), these problems have been fixed in version 8:6974+dfsg-11+deb9u5 We recommend that you u ...