384
VMScore

CVE-2018-6405

Published: 30/01/2018 Updated: 28/04/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

In the ReadDCMImage function in coders/dcm.c in ImageMagick prior to 7.0.7-23, each redmap, greenmap, and bluemap variable can be overwritten by a new pointer. The previous pointer is lost, which leads to a memory leak. This allows remote malicious users to cause a denial of service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

imagemagick imagemagick

canonical ubuntu linux 14.04

canonical ubuntu linux 16.04

canonical ubuntu linux 17.10

canonical ubuntu linux 18.04

Vendor Advisories

Several security issues were fixed in ImageMagick ...
In the ReadDCMImage function in coders/dcmc in ImageMagick before 707-23, each redmap, greenmap, and bluemap variable can be overwritten by a new pointer The previous pointer is lost, which leads to a memory leak This allows remote attackers to cause a denial of service ...
Debian Bug report logs - #876488 imagemagick: CVE-2017-14682: Heap buffer overflow in GetNextToken() Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 22 Sep 2017 18:24:0 ...
Debian Bug report logs - #885941 imagemagick: CVE-2017-17681: CPU exhaustion in ReadPSDChannelZip Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 31 Dec 2017 16:21:01 U ...
Debian Bug report logs - #875339 imagemagick: CVE-2017-12692 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 10 Sep 2017 19:09:02 UTC Severity: important Tags: confirm ...
Debian Bug report logs - #877354 imagemagick: CVE-2017-14624: NULL pointer dereference flaw in PostscriptDelegateMessage in coders/psc Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg&g ...
Debian Bug report logs - #875341 imagemagick: CVE-2017-12693 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 10 Sep 2017 19:09:07 UTC Severity: important Tags: confirm ...
Debian Bug report logs - #878527 imagemagick: CVE-2017-14607 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 14 Oct 2017 11:57:02 UTC Severity: serious Tags: confirmed ...
Debian Bug report logs - #876097 imagemagick: CVE-2017-14224: Heap buffer overflow in WritePCXImage Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 18 Sep 2017 12:33:01 ...
Debian Bug report logs - #881392 imagemagick: CVE-2017-16546 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 11 Nov 2017 09:03:02 UTC Severity: grave Tags: confirmed, ...
Debian Bug report logs - #886584 imagemagick: CVE-2017-17914 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 7 Jan 2018 20:54:01 UTC Severity: important Tags: confirm ...
Debian Bug report logs - #876099 imagemagick: CVE-2017-14249 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 18 Sep 2017 13:03:01 UTC Severity: important Tags: confirm ...
Debian Bug report logs - #872373 CVE-2017-12877 Package: imagemagick; Maintainer for imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Source for imagemagick is src:imagemagick (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 16 Aug 2017 21:12:01 ...
Debian Bug report logs - #875506 imagemagick: CVE-2017-14172 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 11 Sep 2017 20:06:02 UTC Severity: normal Tags: confirmed, ...
Debian Bug report logs - #878524 imagemagick: CVE-2017-14626 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 14 Oct 2017 11:42:02 UTC Severity: important Tags: confirm ...
Debian Bug report logs - #875503 imagemagick: CVE-2017-14174 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 11 Sep 2017 20:03:01 UTC Severity: normal Tags: confirmed, ...
Debian Bug report logs - #873134 imagemagick: CVE-2017-12983 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 24 Aug 2017 19:27:01 UTC Severity: serious Tags: confirmed ...
Debian Bug report logs - #875352 imagemagick: CVE-2017-13768 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 10 Sep 2017 20:21:05 UTC Severity: important Tags: confirm ...
Debian Bug report logs - #873100 imagemagick: CVE-2017-13133 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 24 Aug 2017 15:09:01 UTC Severity: important Tags: confirm ...
Debian Bug report logs - #878579 imagemagick: CVE-2017-15281 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 14 Oct 2017 18:51:05 UTC Severity: important Tags: confirm ...
Debian Bug report logs - #878545 imagemagick: CVE-2017-14505 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 14 Oct 2017 13:24:01 UTC Severity: important Tags: confirm ...
Debian Bug report logs - #873871 imagemagick: CVE-2017-12875 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 31 Aug 2017 19:03:01 UTC Severity: important Tags: confirm ...
Debian Bug report logs - #873059 imagemagick: CVE-2017-12140 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 24 Aug 2017 07:09:02 UTC Severity: important Tags: confirm ...
Debian Bug report logs - #886281 imagemagick: CVE-2017-1000445 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 3 Jan 2018 19:48:02 UTC Severity: important Tags: confi ...
Debian Bug report logs - #878546 imagemagick: CVE-2017-14400 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 14 Oct 2017 13:30:02 UTC Severity: important Tags: confirm ...
Debian Bug report logs - #885339 CVE-2017-17499 Package: imagemagick; Maintainer for imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Source for imagemagick is src:imagemagick (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 26 Dec 2017 12:51:01 ...
Debian Bug report logs - #878562 imagemagick: CVE-2017-14989 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 14 Oct 2017 16:51:05 UTC Severity: serious Tags: confirmed ...
Debian Bug report logs - #873099 imagemagick: CVE-2017-13134 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 24 Aug 2017 14:57:02 UTC Severity: serious Tags: confirmed ...
Debian Bug report logs - #885340 CVE-2017-17504 Package: imagemagick; Maintainer for imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Source for imagemagick is src:imagemagick (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 26 Dec 2017 12:51:05 ...
Debian Bug report logs - #876487 imagemagick: CVE-2017-14684: memory leak in ResizeMagickMemory Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 22 Sep 2017 18:21:05 UTC ...
Debian Bug report logs - #872609 imagemagick: CVE-2017-12674 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 19 Aug 2017 08:42:02 UTC Severity: normal Tags: confirmed, ...
Debian Bug report logs - #878548 imagemagick: CVE-2017-14741 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 14 Oct 2017 13:42:02 UTC Severity: important Tags: confirm ...
Debian Bug report logs - #877355 imagemagick: CVE-2017-14625: NULL pointer dereference flaw in sixel_output_create in coders/sixelc Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> ...
Debian Bug report logs - #878555 imagemagick: CVE-2017-15015 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 14 Oct 2017 15:33:01 UTC Severity: important Tags: confirm ...
Debian Bug report logs - #878508 imagemagick: CVE-2017-13758 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 14 Oct 2017 09:03:02 UTC Severity: serious Tags: confirmed ...
Debian Bug report logs - #875338 imagemagick: CVE-2017-12691 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 10 Sep 2017 19:06:01 UTC Severity: important Tags: confirm ...
Debian Bug report logs - #878541 imagemagick: CVE-2017-14532 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 14 Oct 2017 12:57:05 UTC Severity: important Tags: confirm ...
Debian Bug report logs - #875502 imagemagick: CVE-2017-14175 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 11 Sep 2017 20:00:01 UTC Severity: normal Tags: confirmed, ...
Debian Bug report logs - #878547 imagemagick: CVE-2017-14739 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 14 Oct 2017 13:33:02 UTC Severity: important Tags: confirm ...
Debian Bug report logs - #886588 imagemagick: CVE-2018-5248 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 7 Jan 2018 21:15:02 UTC Severity: important Tags: confirme ...
Debian Bug report logs - #875504 imagemagick: CVE-2017-14173 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 11 Sep 2017 20:03:05 UTC Severity: normal Tags: confirmed, ...
Debian Bug report logs - #878507 imagemagick: CVE-2017-13769 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 14 Oct 2017 08:57:02 UTC Severity: serious Tags: confirmed ...
Debian Bug report logs - #885125 imagemagick: CVE-2017-17879: heap-buffer-overflow in ReadOneMNGImage Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 24 Dec 2017 09:45: ...
Debian Bug report logs - #878578 imagemagick: CVE-2017-15277 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 14 Oct 2017 18:51:02 UTC Severity: serious Tags: confirmed ...
Debian Bug report logs - #878506 imagemagick: CVE-2017-14060 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 14 Oct 2017 08:54:01 UTC Severity: important Tags: confirm ...
Debian Bug report logs - #878554 imagemagick: CVE-2017-15017 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 14 Oct 2017 15:15:01 UTC Severity: important Tags: confirm ...
Debian Bug report logs - #885942 imagemagick: CVE-2017-17682: cpu exhaustion in ReadWPGImage Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 31 Dec 2017 16:30:02 UTC S ...
Debian Bug report logs - #876105 imagemagick: CVE-2017-14341: cpu exhaustion in ReadWPGImage Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 18 Sep 2017 13:57:04 UTC S ...
Debian Bug report logs - #873131 imagemagick: CVE-2017-13061 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 24 Aug 2017 19:00:02 UTC Severity: important Tags: confirm ...

Github Repositories

πŸ‘‹ μ•ˆλ…•ν•˜μ„Έμš”! ν”„λ‘œκ·Έλž¨μ„ λΆ„μ„ν•˜κ³  λ³΄μ•ˆ κ΄€μ μœΌλ‘œ ν•΄μ„ν•˜λŠ” 것을 μ¦κΉλ‹ˆλ‹€ 아이디어λ₯Ό κ΅¬ν˜„ν•˜κ³  문제λ₯Ό ν•΄κ²°ν•˜λŠ” 것에 ν₯λ―Έκ°€ μžˆμŠ΅λ‹ˆλ‹€ CTF/PS λ“± 문제 풀이λ₯Ό μ¦κΉλ‹ˆλ‹€ μžμ„Έν•œ λ‚΄μš©μ€ 여기에 -> pumicenotionsite/ πŸ–₯️ κ²½λ ₯ IoTCube (201901 - 202002) λ¦¬μ„œμΉ˜ νŒ€, 직원 취약점 탐μ

πŸ‘‹ μ•ˆλ…•ν•˜μ„Έμš”! ν”„λ‘œκ·Έλž¨μ„ λΆ„μ„ν•˜κ³  λ³΄μ•ˆ κ΄€μ μœΌλ‘œ ν•΄μ„ν•˜λŠ” 것을 μ¦κΉλ‹ˆλ‹€ 아이디어λ₯Ό κ΅¬ν˜„ν•˜κ³  문제λ₯Ό ν•΄κ²°ν•˜λŠ” 것에 ν₯λ―Έκ°€ μžˆμŠ΅λ‹ˆλ‹€ CTF/PS λ“± 문제 풀이λ₯Ό μ¦κΉλ‹ˆλ‹€ μžμ„Έν•œ λ‚΄μš©μ€ 여기에 -> pumicenotionsite/ πŸ–₯️ κ²½λ ₯ IoTCube (201901 - 202002) λ¦¬μ„œμΉ˜ νŒ€, 직원 취약점 탐μ