CVE-2018-16412
Published: 03 September 2018
ImageMagick 7.0.8-11 Q16 has a heap-based buffer over-read in the coders/psd.c ParseImageResourceBlocks function.
Priority
CVSS 3 base score: 8.8
Status
Package | Release | Status |
---|---|---|
imagemagick Launchpad, Ubuntu, Debian |
Upstream |
Needs triage
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Released
(8:6.9.7.4+dfsg-16ubuntu6.7)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Released
(8:6.8.9.9-7ubuntu5.14)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
(trusty was needed)
|
|
Patches: Upstream: https://github.com/ImageMagick/ImageMagick6/commit/4745eb1047617330141e9abfd5ae01236a71ae12 |
Notes
Author | Note |
---|---|
sbeattie | PoC in github issue |
mdeslaur | PoC on 32-bit only |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16412
- https://usn.ubuntu.com/usn/usn-4034-1
- NVD
- Launchpad
- Debian