CVE-2017-11639

Description

When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a heap-based buffer over-read in the WriteCIPImage() function in coders/cip.c, related to the GetPixelLuma function in MagickCore/pixel-accessor.h.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.309

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Imagemagic (x64) 7.0.6Windows
Multiple Vulnerabilities are affected in Imagemagic 7.0.6Windows
Multiple Vulnerabilities are affected in ImageMagick 7.0.6Windows
SUSE-SU-2018:3808-1(SUSE Linux Enterprise Server 11-SP4 ) libMagickCore1-6.4.3.6-78.79.1.i586.rpmLinux
SUSE-SU-2018:3808-1(SUSE Linux Enterprise Server 11-SP4 ) libMagickCore1-6.4.3.6-78.79.1.x86_64.rpmLinux
SUSE-SU-2018:3808-1(SUSE Linux Enterprise Server 11-SP4 ) libMagickCore1-32bit-6.4.3.6-78.79.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234