CVE-2019-10131

An off-by-one read vulnerability was discovered in ImageMagick before version 7.0.7-28 in the formatIPTCfromBuffer function in coders/meta.c. A local attacker may use this flaw to read beyond the end of the buffer or to crash the program.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.1 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 32%
Affected Products (NVD)
VendorProductVersion
imagemagickimagemagick
𝑥
< 6.9.9-40
imagemagickimagemagick
7.0.0-0 ≤
𝑥
< 7.0.7-28
redhatenterprise_linux
7.0
debiandebian_linux
9.0
canonicalubuntu_linux
16.04
canonicalubuntu_linux
18.04
canonicalubuntu_linux
18.10
canonicalubuntu_linux
19.04
opensuseleap
42.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
imagemagick
bookworm
8:6.9.11.60+dfsg-1.6+deb12u2
fixed
bookworm (security)
8:6.9.11.60+dfsg-1.6+deb12u1
fixed
bullseye
8:6.9.11.60+dfsg-1.3+deb11u4
fixed
bullseye (security)
8:6.9.11.60+dfsg-1.3+deb11u3
fixed
jessie
no-dsa
sid
8:7.1.1.39+dfsg1-2
fixed
trixie
8:6.9.13.12+dfsg1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
imagemagick
bionic
Fixed 8:6.9.7.4+dfsg-16ubuntu6.7
released
cosmic
not-affected
disco
not-affected
focal
not-affected
jammy
not-affected
kinetic
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
Fixed 8:6.7.7.10-6ubuntu3.13+esm9
released
xenial
Fixed 8:6.8.9.9-7ubuntu5.14
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
ImageMagick
suse enterprise desktop 12 SP3
6.8.8.1-71.123.2
fixed
suse enterprise desktop 12 SP4
6.8.8.1-71.123.2
fixed
suse enterprise sap 12 SP3
6.8.8.1-71.123.2
fixed
suse enterprise sap 12 SP4
6.8.8.1-71.123.2
fixed
suse enterprise sap 12 SP5
6.8.8.1-71.123.2
fixed
suse enterprise server 12 SP3
6.8.8.1-71.123.2
fixed
suse enterprise server 12 SP4
6.8.8.1-71.123.2
fixed
suse enterprise server 12 SP5
6.8.8.1-71.123.2
fixed
suse enterprise workstation 12 SP3
6.8.8.1-71.123.2
fixed
suse enterprise workstation 12 SP4
6.8.8.1-71.123.2
fixed
suse enterprise workstation 12 SP5
6.8.8.1-71.123.2
fixed
ImageMagick-config-6-SUSE
suse enterprise desktop 12 SP3
6.8.8.1-71.123.2
fixed
suse enterprise desktop 12 SP4
6.8.8.1-71.123.2
fixed
suse enterprise sap 12 SP3
6.8.8.1-71.123.2
fixed
suse enterprise sap 12 SP4
6.8.8.1-71.123.2
fixed
suse enterprise sap 12 SP5
6.8.8.1-71.126.1
fixed
suse enterprise server 12 SP3
6.8.8.1-71.123.2
fixed
suse enterprise server 12 SP4
6.8.8.1-71.123.2
fixed
suse enterprise server 12 SP5
6.8.8.1-71.126.1
fixed
suse enterprise workstation 12 SP3
6.8.8.1-71.123.2
fixed
suse enterprise workstation 12 SP4
6.8.8.1-71.123.2
fixed
ImageMagick-config-6-upstream
suse enterprise desktop 12 SP3
6.8.8.1-71.123.2
fixed
suse enterprise desktop 12 SP4
6.8.8.1-71.123.2
fixed
suse enterprise sap 12 SP3
6.8.8.1-71.123.2
fixed
suse enterprise sap 12 SP4
6.8.8.1-71.123.2
fixed
suse enterprise sap 12 SP5
6.8.8.1-71.126.1
fixed
suse enterprise server 12 SP3
6.8.8.1-71.123.2
fixed
suse enterprise server 12 SP4
6.8.8.1-71.123.2
fixed
suse enterprise server 12 SP5
6.8.8.1-71.126.1
fixed
suse enterprise workstation 12 SP3
6.8.8.1-71.123.2
fixed
suse enterprise workstation 12 SP4
6.8.8.1-71.123.2
fixed
libMagick++-6_Q16-3
suse enterprise desktop 12 SP3
6.8.8.1-71.123.2
fixed
suse enterprise desktop 12 SP4
6.8.8.1-71.123.2
fixed
suse enterprise sap 12 SP3
6.8.8.1-71.123.2
fixed
suse enterprise sap 12 SP4
6.8.8.1-71.123.2
fixed
suse enterprise sap 12 SP5
6.8.8.1-71.123.2
fixed
suse enterprise server 12 SP3
6.8.8.1-71.123.2
fixed
suse enterprise server 12 SP4
6.8.8.1-71.123.2
fixed
suse enterprise server 12 SP5
6.8.8.1-71.123.2
fixed
suse enterprise workstation 12 SP3
6.8.8.1-71.123.2
fixed
suse enterprise workstation 12 SP4
6.8.8.1-71.123.2
fixed
suse enterprise workstation 12 SP5
6.8.8.1-71.123.2
fixed
libMagickCore-6_Q16-1
suse enterprise sap 12 SP3
6.8.8.1-71.123.2
fixed
suse enterprise sap 12 SP4
6.8.8.1-71.123.2
fixed
suse enterprise sap 12 SP5
6.8.8.1-71.126.1
fixed
suse enterprise server 12 SP3
6.8.8.1-71.123.2
fixed
suse enterprise server 12 SP4
6.8.8.1-71.123.2
fixed
suse enterprise server 12 SP5
6.8.8.1-71.126.1
fixed
libMagickCore-6_Q16-1-32bit
suse enterprise desktop 12 SP3
6.8.8.1-71.123.2
fixed
suse enterprise desktop 12 SP4
6.8.8.1-71.123.2
fixed
suse enterprise sap 12 SP3
6.8.8.1-71.123.2
fixed
suse enterprise sap 12 SP4
6.8.8.1-71.123.2
fixed
suse enterprise sap 12 SP5
6.8.8.1-71.123.2
fixed
suse enterprise server 12 SP3
6.8.8.1-71.123.2
fixed
suse enterprise server 12 SP4
6.8.8.1-71.123.2
fixed
suse enterprise server 12 SP5
6.8.8.1-71.123.2
fixed
suse enterprise workstation 12 SP3
6.8.8.1-71.123.2
fixed
suse enterprise workstation 12 SP4
6.8.8.1-71.123.2
fixed
suse enterprise workstation 12 SP5
6.8.8.1-71.123.2
fixed
libMagickWand-6_Q16-1
suse enterprise sap 12 SP3
6.8.8.1-71.123.2
fixed
suse enterprise sap 12 SP4
6.8.8.1-71.123.2
fixed
suse enterprise sap 12 SP5
6.8.8.1-71.126.1
fixed
suse enterprise server 12 SP3
6.8.8.1-71.123.2
fixed
suse enterprise server 12 SP4
6.8.8.1-71.123.2
fixed
suse enterprise server 12 SP5
6.8.8.1-71.126.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
ImageMagick
RHEL 7
0:6.9.10.68-3.el7
fixed
ImageMagick-c
RHEL 7
0:6.9.10.68-3.el7
fixed
ImageMagick-devel
RHEL 7
0:6.9.10.68-3.el7
fixed
ImageMagick-doc
RHEL 7
0:6.9.10.68-3.el7
fixed
ImageMagick-perl
RHEL 7
0:6.9.10.68-3.el7
fixed
autotrace
RHEL 7
0:0.31.1-38.el7
fixed
autotrace-devel
RHEL 7
0:0.31.1-38.el7
fixed
emacs
RHEL 7
1:24.3-23.el7
fixed
emacs-common
RHEL 7
1:24.3-23.el7
fixed
emacs-el
RHEL 7
1:24.3-23.el7
fixed
emacs-filesystem
RHEL 7
1:24.3-23.el7
fixed
emacs-nox
RHEL 7
1:24.3-23.el7
fixed
emacs-terminal
RHEL 7
1:24.3-23.el7
fixed
inkscape
RHEL 7
0:0.92.2-3.el7
fixed
inkscape-docs
RHEL 7
0:0.92.2-3.el7
fixed
inkscape-view
RHEL 7
0:0.92.2-3.el7
fixed