CVE-2019-11470
Description
The cineon parsing component in ImageMagick 7.0.8-26 Q16 allows attackers to cause a denial-of-service (uncontrolled resource consumption) by crafting a Cineon image with an incorrect claimed image size. This occurs because ReadCINImage in coders/cin.c lacks a check for insufficient image data in a file.
Risk Information
Base Score
6.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.741
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple Vulnerabilities are affected in Imagemagic (x64) 7.0.8 | Windows |
| Multiple Vulnerabilities are affected in Imagemagic 7.0.8 | Windows |
| Multiple Vulnerabilities are affected in ImageMagick 7.0.8 | Windows |
| (RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update autotrace-0.31.1-38.el7.i686.rpm | Linux |
| (RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update autotrace-0.31.1-38.el7.x86_64.rpm | Linux |
| (RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update autotrace-devel-0.31.1-38.el7.i686.rpm | Linux |
| (RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update autotrace-devel-0.31.1-38.el7.x86_64.rpm | Linux |
| (RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update inkscape-0.92.2-3.el7.x86_64.rpm | Linux |
| (RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update inkscape-docs-0.92.2-3.el7.x86_64.rpm | Linux |
| (RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update inkscape-view-0.92.2-3.el7.x86_64.rpm | Linux |
| (RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update ImageMagick-6.9.10.68-3.el7.i686.rpm | Linux |
| (RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update ImageMagick-6.9.10.68-3.el7.x86_64.rpm | Linux |
| (RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update ImageMagick-c++-6.9.10.68-3.el7.i686.rpm | Linux |
| (RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update ImageMagick-c++-6.9.10.68-3.el7.x86_64.rpm | Linux |
| (RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update ImageMagick-c++-devel-6.9.10.68-3.el7.i686.rpm | Linux |
| (RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update ImageMagick-c++-devel-6.9.10.68-3.el7.x86_64.rpm | Linux |
| (RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update ImageMagick-devel-6.9.10.68-3.el7.i686.rpm | Linux |
| (RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update ImageMagick-devel-6.9.10.68-3.el7.x86_64.rpm | Linux |
| (RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update ImageMagick-doc-6.9.10.68-3.el7.x86_64.rpm | Linux |
| (RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update ImageMagick-perl-6.9.10.68-3.el7.x86_64.rpm | Linux |
| (RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update emacs-24.3-23.el7.x86_64.rpm | Linux |
| (RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update emacs-common-24.3-23.el7.x86_64.rpm | Linux |
| (RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update emacs-el-24.3-23.el7.noarch.rpm | Linux |
| (RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update emacs-filesystem-24.3-23.el7.noarch.rpm | Linux |
| (RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update emacs-nox-24.3-23.el7.x86_64.rpm | Linux |
| (RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update emacs-terminal-24.3-23.el7.noarch.rpm | Linux |
| imagemagick security update(DSA-4712-1) imagemagick_6.9.10.23+dfsg-2.1+deb10u1_i386.deb | Linux |
| imagemagick security update(DSA-4712-1) imagemagick_6.9.10.23+dfsg-2.1+deb10u1_amd64.deb | Linux |
| (CESA-2020:1180) ImageMagick security, bug fix, and enhancement update autotrace-0.31.1-38.el7.x86_64.rpm | Linux |
| (CESA-2020:1180) ImageMagick security, bug fix, and enhancement update autotrace-devel-0.31.1-38.el7.x86_64.rpm | Linux |
| (CESA-2020:1180) ImageMagick security, bug fix, and enhancement update emacs-24.3-23.el7.x86_64.rpm | Linux |
| (CESA-2020:1180) ImageMagick security, bug fix, and enhancement update emacs-common-24.3-23.el7.x86_64.rpm | Linux |
| (CESA-2020:1180) ImageMagick security, bug fix, and enhancement update emacs-el-24.3-23.el7.noarch.rpm | Linux |
| (CESA-2020:1180) ImageMagick security, bug fix, and enhancement update emacs-filesystem-24.3-23.el7.noarch.rpm | Linux |
| (CESA-2020:1180) ImageMagick security, bug fix, and enhancement update emacs-nox-24.3-23.el7.x86_64.rpm | Linux |
| (CESA-2020:1180) ImageMagick security, bug fix, and enhancement update emacs-terminal-24.3-23.el7.noarch.rpm | Linux |
| (CESA-2020:1180) ImageMagick security, bug fix, and enhancement update inkscape-0.92.2-3.el7.x86_64.rpm | Linux |
| (CESA-2020:1180) ImageMagick security, bug fix, and enhancement update inkscape-docs-0.92.2-3.el7.x86_64.rpm | Linux |
| (CESA-2020:1180) ImageMagick security, bug fix, and enhancement update inkscape-view-0.92.2-3.el7.x86_64.rpm | Linux |
| (RHSA-2020:1180)Moderate: security, bug fix, and enhancement update ImageMagick-debuginfo-6.9.10.68-3.el7.i686.rpm | Linux |
| (RHSA-2020:1180)Moderate: security, bug fix, and enhancement update ImageMagick-debuginfo-6.9.10.68-3.el7.x86_64.rpm | Linux |
| (RHSA-2020:1180)Moderate: security, bug fix, and enhancement update autotrace-debuginfo-0.31.1-38.el7.i686.rpm | Linux |
| (RHSA-2020:1180)Moderate: security, bug fix, and enhancement update autotrace-debuginfo-0.31.1-38.el7.x86_64.rpm | Linux |
| (RHSA-2020:1180)Moderate: security, bug fix, and enhancement update emacs-debuginfo-24.3-23.el7.x86_64.rpm | Linux |
| (RHSA-2020:1180)Moderate: security, bug fix, and enhancement update inkscape-debuginfo-0.92.2-3.el7.x86_64.rpm | Linux |
| ImageMagick update (ELSA-2020-1180) ImageMagick-6.9.10.68-3.el7.i686.rpm | Linux |
| ImageMagick update (ELSA-2020-1180) ImageMagick-6.9.10.68-3.el7.x86_64.rpm | Linux |
| ImageMagick-c++ update (ELSA-2020-1180) ImageMagick-c++-6.9.10.68-3.el7.i686.rpm | Linux |
| ImageMagick-c++ update (ELSA-2020-1180) ImageMagick-c++-6.9.10.68-3.el7.x86_64.rpm | Linux |
| ImageMagick-perl update (ELSA-2020-1180) ImageMagick-perl-6.9.10.68-3.el7.x86_64.rpm | Linux |
| Emacs update (ELSA-2020-1180) emacs-24.3-23.el7.x86_64.rpm | Linux |
| Emacs-common update (ELSA-2020-1180) emacs-common-24.3-23.el7.x86_64.rpm | Linux |
| Emacs-filesystem update (ELSA-2020-1180) emacs-filesystem-24.3-23.el7.noarch.rpm | Linux |
| Emacs-nox update (ELSA-2020-1180) emacs-nox-24.3-23.el7.x86_64.rpm | Linux |
| Inkscape update (ELSA-2020-1180) inkscape-0.92.2-3.el7.x86_64.rpm | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234