CVE-2018-16323

Description

ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If the affected code is used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
87.78

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Imagemagic (x64) 7.0.8Windows
Multiple Vulnerabilities are affected in Imagemagic 7.0.8Windows
Multiple Vulnerabilities are affected in ImageMagick 7.0.8Windows
SUSE-SU-2018:3348-1(SUSE Linux Enterprise Server 11-SP4 ) libMagickCore1-6.4.3.6-78.74.1.i586.rpmLinux
SUSE-SU-2018:3348-1(SUSE Linux Enterprise Server 11-SP4 ) libMagickCore1-6.4.3.6-78.74.1.x86_64.rpmLinux
SUSE-SU-2018:3348-1(SUSE Linux Enterprise Server 11-SP4 ) libMagickCore1-32bit-6.4.3.6-78.74.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234