C’è un controllo mancante per lunghezza nelle funzioni ReadDCMImage di codificatori / dcm.c e ReadPICTImage di codificatori / pict.c in ImageMagick 7.0.8-11, che consente agli aggressori remoti di provocare una negazione del servizio tramite un’immagine predisposto. |
https://www.debian.org/security/2018/dsa-4316 https://github.com/ImageMagick/ImageMagick/commit/16916c8979c32765c542e216b31cee2671b7afe7 https://github.com/ImageMagick/ImageMagick/commit/afa878a689870c28b6994ecf3bb8dbfb2b76d135 https://github.com/ImageMagick/ImageMagick/issues/1269 https://lists.debian.org/debian-lts-announce/2018/10/msg00002.html http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00006.html https://usn.ubuntu.com/3785-1/ https://usn.ubuntu.com/4034-1/ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16644 |
Vulnerabilità: CVE-2018-16644
