CVE-2018-11251
18.05.2018, 19:29
In ImageMagick 7.0.7-23 Q16 x86_64 2018-01-24, there is a heap-based buffer over-read in ReadSUNImage in coders/sun.c, which allows attackers to cause a denial of service (application crash in SetGrayscaleImage in MagickCore/quantize.c) via a crafted SUN image file.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| imagemagick | imagemagick | 7.0.7-16 ≤ 𝑥 < 7.0.7-21 |
| imagemagick | imagemagick | 7.0.7-23 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ImageMagick |
| ||||||||||||||||||||||
| ImageMagick-config-6-SUSE |
| ||||||||||||||||||||||
| ImageMagick-config-6-upstream |
| ||||||||||||||||||||||
| libMagick++-6_Q16-3 |
| ||||||||||||||||||||||
| libMagickCore-6_Q16-1 |
| ||||||||||||||||||||||
| libMagickCore-6_Q16-1-32bit |
| ||||||||||||||||||||||
| libMagickWand-6_Q16-1 |
|
Common Weakness Enumeration
References