CVE-2019-19948

Description

In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the function WriteSGIImage of coders/sgi.c.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.387

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Imagemagic (x64) 7.0.8Windows
Multiple Vulnerabilities are affected in Imagemagic 7.0.8Windows
Multiple Vulnerabilities are affected in ImageMagick 7.0.8Windows
SUSE-SU-2020:0411-1(SUSE Linux Enterprise Desktop 12-SP4 ) ImageMagick-6.8.8.1-71.141.1.x86_64.rpmLinux
SUSE-SU-2020:0411-1(SUSE Linux Enterprise Desktop 12-SP4 ) ImageMagick-config-6-SUSE-6.8.8.1-71.141.1.x86_64.rpmLinux
SUSE-SU-2020:0411-1(SUSE Linux Enterprise Desktop 12-SP4 ) ImageMagick-config-6-upstream-6.8.8.1-71.141.1.x86_64.rpmLinux
SUSE-SU-2020:0411-1(SUSE Linux Enterprise Desktop 12-SP4 ) ImageMagick-debuginfo-6.8.8.1-71.141.1.x86_64.rpmLinux
SUSE-SU-2020:0411-1(SUSE Linux Enterprise Desktop 12-SP4 ) ImageMagick-debugsource-6.8.8.1-71.141.1.x86_64.rpmLinux
SUSE-SU-2020:0411-1(SUSE Linux Enterprise Desktop 12-SP4 ) libMagick++-6_Q16-3-6.8.8.1-71.141.1.x86_64.rpmLinux
SUSE-SU-2020:0411-1(SUSE Linux Enterprise Desktop 12-SP4 ) libMagick++-6_Q16-3-debuginfo-6.8.8.1-71.141.1.x86_64.rpmLinux
SUSE-SU-2020:0411-1(SUSE Linux Enterprise Desktop 12-SP4 ) libMagickCore-6_Q16-1-6.8.8.1-71.141.1.x86_64.rpmLinux
SUSE-SU-2020:0411-1(SUSE Linux Enterprise Desktop 12-SP4 ) libMagickCore-6_Q16-1-32bit-6.8.8.1-71.141.1.x86_64.rpmLinux
SUSE-SU-2020:0411-1(SUSE Linux Enterprise Desktop 12-SP4 ) libMagickCore-6_Q16-1-debuginfo-6.8.8.1-71.141.1.x86_64.rpmLinux
SUSE-SU-2020:0411-1(SUSE Linux Enterprise Desktop 12-SP4 ) libMagickCore-6_Q16-1-debuginfo-32bit-6.8.8.1-71.141.1.x86_64.rpmLinux
SUSE-SU-2020:0411-1(SUSE Linux Enterprise Desktop 12-SP4 ) libMagickWand-6_Q16-1-6.8.8.1-71.141.1.x86_64.rpmLinux
SUSE-SU-2020:0411-1(SUSE Linux Enterprise Desktop 12-SP4 ) libMagickWand-6_Q16-1-debuginfo-6.8.8.1-71.141.1.x86_64.rpmLinux
(RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update autotrace-0.31.1-38.el7.i686.rpmLinux
(RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update autotrace-0.31.1-38.el7.x86_64.rpmLinux
(RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update autotrace-devel-0.31.1-38.el7.i686.rpmLinux
(RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update autotrace-devel-0.31.1-38.el7.x86_64.rpmLinux
(RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update inkscape-0.92.2-3.el7.x86_64.rpmLinux
(RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update inkscape-docs-0.92.2-3.el7.x86_64.rpmLinux
(RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update inkscape-view-0.92.2-3.el7.x86_64.rpmLinux
(RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update ImageMagick-6.9.10.68-3.el7.i686.rpmLinux
(RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update ImageMagick-6.9.10.68-3.el7.x86_64.rpmLinux
(RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update ImageMagick-c++-6.9.10.68-3.el7.i686.rpmLinux
(RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update ImageMagick-c++-6.9.10.68-3.el7.x86_64.rpmLinux
(RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update ImageMagick-c++-devel-6.9.10.68-3.el7.i686.rpmLinux
(RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update ImageMagick-c++-devel-6.9.10.68-3.el7.x86_64.rpmLinux
(RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update ImageMagick-devel-6.9.10.68-3.el7.i686.rpmLinux
(RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update ImageMagick-devel-6.9.10.68-3.el7.x86_64.rpmLinux
(RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update ImageMagick-doc-6.9.10.68-3.el7.x86_64.rpmLinux
(RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update ImageMagick-perl-6.9.10.68-3.el7.x86_64.rpmLinux
(RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update emacs-24.3-23.el7.x86_64.rpmLinux
(RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update emacs-common-24.3-23.el7.x86_64.rpmLinux
(RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update emacs-el-24.3-23.el7.noarch.rpmLinux
(RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update emacs-filesystem-24.3-23.el7.noarch.rpmLinux
(RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update emacs-nox-24.3-23.el7.x86_64.rpmLinux
(RHSA-2020:1180) ImageMagick security, bug fix, and enhancement update emacs-terminal-24.3-23.el7.noarch.rpmLinux
imagemagick security update(DSA-4712-1) imagemagick_6.9.10.23+dfsg-2.1+deb10u1_i386.debLinux
imagemagick security update(DSA-4712-1) imagemagick_6.9.10.23+dfsg-2.1+deb10u1_amd64.debLinux
imagemagick security update(DSA-4715-1) imagemagick_6.9.7.4+dfsg-11+deb9u8_i386.debLinux
imagemagick security update(DSA-4715-1) imagemagick_6.9.7.4+dfsg-11+deb9u8_amd64.debLinux
Image manipulation programs and library (USN-4549-1) imagemagick_6.9.10.23+dfsg-2.1ubuntu11.1_i386.debLinux
Image manipulation programs and library (USN-4549-1) imagemagick_6.9.10.23+dfsg-2.1ubuntu11.1_amd64.debLinux
Image manipulation programs and library (USN-4549-1) libmagick++-6.q16-8_6.9.10.23+dfsg-2.1ubuntu11.1_i386.debLinux
Image manipulation programs and library (USN-4549-1) libmagick++-6.q16-8_6.9.10.23+dfsg-2.1ubuntu11.1_amd64.debLinux
Image manipulation programs and library (USN-4549-1) libmagickcore-6.q16-6_6.9.10.23+dfsg-2.1ubuntu11.1_i386.debLinux
Image manipulation programs and library (USN-4549-1) libmagickcore-6.q16-6_6.9.10.23+dfsg-2.1ubuntu11.1_amd64.debLinux
Image manipulation programs and library (USN-4670-1) imagemagick_6.8.9.9-7ubuntu5.16_i386.debLinux
Image manipulation programs and library (USN-4670-1) imagemagick_6.8.9.9-7ubuntu5.16_amd64.debLinux
Image manipulation programs and library (USN-4670-1) imagemagick_6.9.7.4+dfsg-16ubuntu6.9_i386.debLinux
Image manipulation programs and library (USN-4670-1) imagemagick_6.9.7.4+dfsg-16ubuntu6.9_amd64.debLinux
Image manipulation programs and library (USN-4670-1) imagemagick_6.9.10.23+dfsg-2.1ubuntu11.2_i386.debLinux
Image manipulation programs and library (USN-4670-1) imagemagick_6.9.10.23+dfsg-2.1ubuntu11.2_amd64.debLinux
Image manipulation programs and library (USN-4670-1) imagemagick_6.9.10.23+dfsg-2.1ubuntu13.1_i386.debLinux
Image manipulation programs and library (USN-4670-1) imagemagick_6.9.10.23+dfsg-2.1ubuntu13.1_amd64.debLinux
Image manipulation programs and library (USN-4670-1) libmagick++-6.q16-7_6.9.7.4+dfsg-16ubuntu6.9_i386.debLinux
Image manipulation programs and library (USN-4670-1) libmagick++-6.q16-7_6.9.7.4+dfsg-16ubuntu6.9_amd64.debLinux
Image manipulation programs and library (USN-4670-1) libmagick++-6.q16-8_6.9.10.23+dfsg-2.1ubuntu11.2_i386.debLinux
Image manipulation programs and library (USN-4670-1) libmagick++-6.q16-8_6.9.10.23+dfsg-2.1ubuntu11.2_amd64.debLinux
Image manipulation programs and library (USN-4670-1) libmagick++-6.q16-8_6.9.10.23+dfsg-2.1ubuntu13.1_i386.debLinux
Image manipulation programs and library (USN-4670-1) libmagick++-6.q16-8_6.9.10.23+dfsg-2.1ubuntu13.1_amd64.debLinux
Image manipulation programs and library (USN-4670-1) libmagickcore-6.q16-3_6.9.7.4+dfsg-16ubuntu6.9_i386.debLinux
Image manipulation programs and library (USN-4670-1) libmagickcore-6.q16-3_6.9.7.4+dfsg-16ubuntu6.9_amd64.debLinux
Image manipulation programs and library (USN-4670-1) libmagickcore-6.q16-6_6.9.10.23+dfsg-2.1ubuntu11.2_i386.debLinux
Image manipulation programs and library (USN-4670-1) libmagickcore-6.q16-6_6.9.10.23+dfsg-2.1ubuntu11.2_amd64.debLinux
Image manipulation programs and library (USN-4670-1) libmagickcore-6.q16-6_6.9.10.23+dfsg-2.1ubuntu13.1_i386.debLinux
Image manipulation programs and library (USN-4670-1) libmagickcore-6.q16-6_6.9.10.23+dfsg-2.1ubuntu13.1_amd64.debLinux
Image manipulation programs and library (USN-4670-1) libmagickwand-6.q16-3_6.9.7.4+dfsg-16ubuntu6.9_i386.debLinux
Image manipulation programs and library (USN-4670-1) libmagickwand-6.q16-3_6.9.7.4+dfsg-16ubuntu6.9_amd64.debLinux
Image manipulation programs and library (USN-4670-1) libmagickwand-6.q16-6_6.9.10.23+dfsg-2.1ubuntu11.2_i386.debLinux
Image manipulation programs and library (USN-4670-1) libmagickwand-6.q16-6_6.9.10.23+dfsg-2.1ubuntu11.2_amd64.debLinux
Image manipulation programs and library (USN-4670-1) libmagickwand-6.q16-6_6.9.10.23+dfsg-2.1ubuntu13.1_i386.debLinux
Image manipulation programs and library (USN-4670-1) libmagickwand-6.q16-6_6.9.10.23+dfsg-2.1ubuntu13.1_amd64.debLinux
Image manipulation programs and library (USN-4670-1) libmagick++-6.q16hdri-7_6.9.7.4+dfsg-16ubuntu6.9_i386.debLinux
Image manipulation programs and library (USN-4670-1) libmagick++-6.q16hdri-7_6.9.7.4+dfsg-16ubuntu6.9_amd64.debLinux
Image manipulation programs and library (USN-4670-1) libmagick++-6.q16hdri-8_6.9.10.23+dfsg-2.1ubuntu11.2_i386.debLinux
Image manipulation programs and library (USN-4670-1) libmagick++-6.q16hdri-8_6.9.10.23+dfsg-2.1ubuntu11.2_amd64.debLinux
Image manipulation programs and library (USN-4670-1) libmagick++-6.q16hdri-8_6.9.10.23+dfsg-2.1ubuntu13.1_i386.debLinux
Image manipulation programs and library (USN-4670-1) libmagick++-6.q16hdri-8_6.9.10.23+dfsg-2.1ubuntu13.1_amd64.debLinux
Image manipulation programs and library (USN-4670-1) libmagickcore-6.q16hdri-3_6.9.7.4+dfsg-16ubuntu6.9_i386.debLinux
Image manipulation programs and library (USN-4670-1) libmagickcore-6.q16hdri-3_6.9.7.4+dfsg-16ubuntu6.9_amd64.debLinux
Image manipulation programs and library (USN-4670-1) libmagickcore-6.q16hdri-6_6.9.10.23+dfsg-2.1ubuntu11.2_i386.debLinux
Image manipulation programs and library (USN-4670-1) libmagickcore-6.q16hdri-6_6.9.10.23+dfsg-2.1ubuntu11.2_amd64.debLinux
Image manipulation programs and library (USN-4670-1) libmagickcore-6.q16hdri-6_6.9.10.23+dfsg-2.1ubuntu13.1_i386.debLinux
Image manipulation programs and library (USN-4670-1) libmagickcore-6.q16hdri-6_6.9.10.23+dfsg-2.1ubuntu13.1_amd64.debLinux
Image manipulation programs and library (USN-4670-1) libmagickwand-6.q16hdri-3_6.9.7.4+dfsg-16ubuntu6.9_i386.debLinux
Image manipulation programs and library (USN-4670-1) libmagickwand-6.q16hdri-3_6.9.7.4+dfsg-16ubuntu6.9_amd64.debLinux
Image manipulation programs and library (USN-4670-1) libmagickwand-6.q16hdri-6_6.9.10.23+dfsg-2.1ubuntu11.2_i386.debLinux
Image manipulation programs and library (USN-4670-1) libmagickwand-6.q16hdri-6_6.9.10.23+dfsg-2.1ubuntu11.2_amd64.debLinux
Image manipulation programs and library (USN-4670-1) libmagickwand-6.q16hdri-6_6.9.10.23+dfsg-2.1ubuntu13.1_i386.debLinux
Image manipulation programs and library (USN-4670-1) libmagickwand-6.q16hdri-6_6.9.10.23+dfsg-2.1ubuntu13.1_amd64.debLinux
Image manipulation programs and library (USN-4670-1) libmagickcore-6.q16-2_6.8.9.9-7ubuntu5.16_i386.debLinux
Image manipulation programs and library (USN-4670-1) libmagickcore-6.q16-2_6.8.9.9-7ubuntu5.16_amd64.debLinux
(CESA-2020:1180) ImageMagick security, bug fix, and enhancement update autotrace-0.31.1-38.el7.x86_64.rpmLinux
(CESA-2020:1180) ImageMagick security, bug fix, and enhancement update autotrace-devel-0.31.1-38.el7.x86_64.rpmLinux
(CESA-2020:1180) ImageMagick security, bug fix, and enhancement update emacs-24.3-23.el7.x86_64.rpmLinux
(CESA-2020:1180) ImageMagick security, bug fix, and enhancement update emacs-common-24.3-23.el7.x86_64.rpmLinux
(CESA-2020:1180) ImageMagick security, bug fix, and enhancement update emacs-el-24.3-23.el7.noarch.rpmLinux
(CESA-2020:1180) ImageMagick security, bug fix, and enhancement update emacs-filesystem-24.3-23.el7.noarch.rpmLinux
(CESA-2020:1180) ImageMagick security, bug fix, and enhancement update emacs-nox-24.3-23.el7.x86_64.rpmLinux
(CESA-2020:1180) ImageMagick security, bug fix, and enhancement update emacs-terminal-24.3-23.el7.noarch.rpmLinux
(CESA-2020:1180) ImageMagick security, bug fix, and enhancement update inkscape-0.92.2-3.el7.x86_64.rpmLinux
(CESA-2020:1180) ImageMagick security, bug fix, and enhancement update inkscape-docs-0.92.2-3.el7.x86_64.rpmLinux
(CESA-2020:1180) ImageMagick security, bug fix, and enhancement update inkscape-view-0.92.2-3.el7.x86_64.rpmLinux
(RHSA-2020:1180)Moderate: security, bug fix, and enhancement update ImageMagick-debuginfo-6.9.10.68-3.el7.i686.rpmLinux
(RHSA-2020:1180)Moderate: security, bug fix, and enhancement update ImageMagick-debuginfo-6.9.10.68-3.el7.x86_64.rpmLinux
(RHSA-2020:1180)Moderate: security, bug fix, and enhancement update autotrace-debuginfo-0.31.1-38.el7.i686.rpmLinux
(RHSA-2020:1180)Moderate: security, bug fix, and enhancement update autotrace-debuginfo-0.31.1-38.el7.x86_64.rpmLinux
(RHSA-2020:1180)Moderate: security, bug fix, and enhancement update emacs-debuginfo-24.3-23.el7.x86_64.rpmLinux
(RHSA-2020:1180)Moderate: security, bug fix, and enhancement update inkscape-debuginfo-0.92.2-3.el7.x86_64.rpmLinux
Image manipulation programs and library (USN-4670-1) libmagickcore-6.q16hdri-3_6.9.7.4+dfsg-16ubuntu6.9_i386.debLinux
Image manipulation programs and library (USN-4670-1) libmagickcore-6.q16hdri-3_6.9.7.4+dfsg-16ubuntu6.9_amd64.debLinux
Image manipulation programs and library (USN-4670-1) libmagickcore-6.q16hdri-6_6.9.10.23+dfsg-2.1ubuntu11.2_i386.debLinux
Image manipulation programs and library (USN-4670-1) libmagickcore-6.q16hdri-6_6.9.10.23+dfsg-2.1ubuntu11.2_amd64.debLinux
Image manipulation programs and library (USN-4670-1) libmagickwand-6.q16hdri-3_6.9.7.4+dfsg-16ubuntu6.9_i386.debLinux
Image manipulation programs and library (USN-4670-1) libmagickwand-6.q16hdri-3_6.9.7.4+dfsg-16ubuntu6.9_amd64.debLinux
Image manipulation programs and library (USN-4670-1) libmagickwand-6.q16hdri-6_6.9.10.23+dfsg-2.1ubuntu11.2_i386.debLinux
Image manipulation programs and library (USN-4670-1) libmagickwand-6.q16hdri-6_6.9.10.23+dfsg-2.1ubuntu11.2_amd64.debLinux
Image manipulation programs and library (USN-4670-1) libmagickcore-6.q16hdri-3-extra_6.9.7.4+dfsg-16ubuntu6.9_i386.debLinux
Image manipulation programs and library (USN-4670-1) libmagickcore-6.q16hdri-3-extra_6.9.7.4+dfsg-16ubuntu6.9_amd64.debLinux
Image manipulation programs and library (USN-4670-1) libmagickcore-6.q16hdri-6-extra_6.9.10.23+dfsg-2.1ubuntu11.2_i386.debLinux
Image manipulation programs and library (USN-4670-1) libmagickcore-6.q16hdri-6-extra_6.9.10.23+dfsg-2.1ubuntu11.2_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234