CVE-2017-10928

Description

In ImageMagick 7.0.6-0, a heap-based buffer over-read in the GetNextToken function in token.c allows remote attackers to obtain sensitive information from process memory or possibly have unspecified other impact via a crafted SVG document that is mishandled in the GetUserSpaceCoordinateValue function in coders/svg.c.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.184

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Imagemagic (x64) 7.0.6Windows
Multiple Vulnerabilities are affected in Imagemagic 7.0.6Windows
Multiple Vulnerabilities are affected in ImageMagick 7.0.6Windows
Image manipulation programs and library (USN-3302-1) libmagick++-6.q16-7_6.9.7.4+dfsg-3ubuntu1.2_i386.debLinux
Image manipulation programs and library (USN-3302-1) libmagick++-6.q16-7_6.9.7.4+dfsg-3ubuntu1.2_amd64.debLinux
Image manipulation programs and library (USN-3302-1) libmagickcore-6.q16-3_6.9.7.4+dfsg-3ubuntu1.2_i386.debLinux
Image manipulation programs and library (USN-3302-1) libmagickcore-6.q16-3_6.9.7.4+dfsg-3ubuntu1.2_amd64.debLinux
Imagemagick 6.9.7.4 dfsg-3ubuntu1.1 for Ubuntu 17.04 (x64) imagemagick_6.9.7.4+dfsg-3ubuntu1.2_amd64.debLinux
Imagemagick 6.9.7.4 dfsg-3ubuntu1.1 for Ubuntu 17.04 imagemagick_6.9.7.4+dfsg-3ubuntu1.2_i386.debLinux
Image manipulation programs and library (USN-3363-1) imagemagick_6.7.7.10-6ubuntu3.8_i386.debLinux
Image manipulation programs and library (USN-3363-1) imagemagick_6.9.7.4+dfsg-3ubuntu1.2_i386.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234