ImageMagick
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*
- < 7.1.2-16
- < 6.9.13-41
A stack buffer overflow vulnerability has been identified in ImageMagick's morphology kernel parsing functions, prior to versions 7.1.2-16 and 6.9.13-41. The issue arises because user-controlled kernel strings that exceed a certain length are copied into fixed-size stack buffers using memcpy, without proper bounds checking. This flaw leads to stack corruption.
Exploitation of this vulnerability causes stack corruption, which can potentially be exploited to execute arbitrary code.
Users can upgrade to ImageMagick versions 7.1.2-16 or 6.9.13-41 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.