8.8
CVSSv3

CVE-2018-9135

Published: 30/03/2018 Updated: 03/10/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

In ImageMagick 7.0.7-24 Q16, there is a heap-based buffer over-read in IsWEBPImageLossless in coders/webp.c.

Vulnerable Product Search on Vulmon Subscribe to Product

imagemagick imagemagick 7.0.7-24

Vendor Advisories

Debian Bug report logs - #904713 imagemagick: CVE-2018-14551: use of uninitialized variable Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 27 Jul 2018 04:18:01 UTC Se ...