ZeroHour

CVE-2019-10131

CVSS 3.1
7.1 high
EPSS
1%p68
Published
()
Modified
Description

An off-by-one read vulnerability was discovered in ImageMagick before version 7.0.7-28 in the formatIPTCfromBuffer function in coders/meta.c. A local attacker may use this flaw to read beyond the end of the buffer or to crash the program.

Vendors
imagemagickredhatdebiancanonicalopensuse
Products
imagemagick, enterprise linux, debian linux, ubuntu linux, leap
Weakness
CWE-193
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.