ImageMagick
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*
- < 7.1.2-15
- < 6.9.13-40
A heap-buffer-overflow read vulnerability has been identified in ImageMagick versions prior to 7.1.2-15 and 6.9.13-40. This vulnerability arises in the GetPixelIndex function, where the OpenPixelCache method updates image channel metadata before allocating memory for the pixel cache. Attackers can exploit this flaw by causing memory and disk allocation failures, leading to a heap-buffer-overflow read that affects any writer using GetPixelIndex.
Exploitation of this vulnerability causes a heap-buffer-overflow read, which can lead to memory corruption and potentially allow for arbitrary code execution.
Users can upgrade to ImageMagick versions 7.1.2-15 or 6.9.13-40 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.