CVE-2017-10995

Description

The mng_get_long function in coders/png.c in ImageMagick 7.0.6-0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted MNG image.

Risk Information

Base Score
5.5
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.425

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Imagemagic (x64) 7.0.6Windows
Multiple Vulnerabilities are affected in Imagemagic 7.0.6Windows
Multiple Vulnerabilities are affected in ImageMagick 7.0.6Windows
Image manipulation programs and library (USN-3363-2) imagemagick_6.8.9.9-7ubuntu5.11_amd64.debLinux
Image manipulation programs and library (USN-3363-2) imagemagick_6.7.7.10-6ubuntu3.11_amd64.debLinux
Image manipulation programs and library (USN-3363-2) libmagick++5_6.7.7.10-6ubuntu3.11_amd64.debLinux
Image manipulation programs and library (USN-3222-1) imagemagick_6.8.9.9-7ubuntu5.11_amd64.debLinux
Image manipulation programs and library (USN-3222-1) imagemagick_6.7.7.10-6ubuntu3.11_amd64.debLinux
Image manipulation programs and library (USN-3222-1) libmagick++5_6.7.7.10-6ubuntu3.11_amd64.debLinux
Image manipulation programs and library (USN-3681-1) imagemagick_6.8.9.9-7ubuntu5.11_i386.debLinux
Image manipulation programs and library (USN-3681-1) imagemagick_6.7.7.10-6ubuntu3.11_i386.debLinux
Image manipulation programs and library (USN-3681-1) imagemagick_6.9.7.4+dfsg-16ubuntu2.2_i386.debLinux
Image manipulation programs and library (USN-3681-1) imagemagick_6.9.7.4+dfsg-16ubuntu2.2_amd64.debLinux
Image manipulation programs and library (USN-3681-1) imagemagick_6.9.7.4+dfsg-16ubuntu6.2_i386.debLinux
Image manipulation programs and library (USN-3681-1) imagemagick_6.9.7.4+dfsg-16ubuntu6.2_amd64.debLinux
Image manipulation programs and library (USN-3681-1) libmagick++5_6.7.7.10-6ubuntu3.11_i386.debLinux
Image manipulation programs and library (USN-3681-1) libmagickcore5_6.7.7.10-6ubuntu3.11_i386.debLinux
Image manipulation programs and library (USN-3681-1) libmagickcore5_6.7.7.10-6ubuntu3.11_amd64.debLinux
Image manipulation programs and library (USN-3681-1) libmagick++-6.q16-7_6.9.7.4+dfsg-16ubuntu2.2_i386.debLinux
Image manipulation programs and library (USN-3681-1) libmagick++-6.q16-7_6.9.7.4+dfsg-16ubuntu2.2_amd64.debLinux
Image manipulation programs and library (USN-3681-1) libmagick++-6.q16-7_6.9.7.4+dfsg-16ubuntu6.2_i386.debLinux
Image manipulation programs and library (USN-3681-1) libmagick++-6.q16-7_6.9.7.4+dfsg-16ubuntu6.2_amd64.debLinux
Image manipulation programs and library (USN-3681-1) libmagickcore-6.q16-3_6.9.7.4+dfsg-16ubuntu2.2_i386.debLinux
Image manipulation programs and library (USN-3681-1) libmagickcore-6.q16-3_6.9.7.4+dfsg-16ubuntu2.2_amd64.debLinux
Image manipulation programs and library (USN-3681-1) libmagickcore-6.q16-3_6.9.7.4+dfsg-16ubuntu6.2_i386.debLinux
Image manipulation programs and library (USN-3681-1) libmagickcore-6.q16-3_6.9.7.4+dfsg-16ubuntu6.2_amd64.debLinux
Image manipulation programs and library (USN-3681-1) libmagickcore-6.q16-2_6.8.9.9-7ubuntu5.11_i386.debLinux
Image manipulation programs and library (USN-3681-1) libmagickcore-6.q16-2_6.8.9.9-7ubuntu5.11_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234