ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If the affected code is used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data.
https://github.com/ImageMagick/ImageMagick/commit/216d117f05bff87b9dc4db55a1b1fadb38bcb786
https://usn.ubuntu.com/3785-1/
Source: MITRE
Published: 2018-09-01
Updated: 2019-06-25
Type: CWE-200
Base Score: 4.3
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N
Impact Score: 2.9
Exploitability Score: 8.6
Severity: MEDIUM
Base Score: 6.5
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Impact Score: 3.6
Exploitability Score: 2.8
Severity: MEDIUM
OR
OR
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
135519 | EulerOS 2.0 SP3 : ImageMagick (EulerOS-SA-2020-1390) | Nessus | Huawei Local Security Checks | high |
131846 | EulerOS 2.0 SP2 : ImageMagick (EulerOS-SA-2019-2354) | Nessus | Huawei Local Security Checks | high |
130869 | EulerOS 2.0 SP5 : ImageMagick (EulerOS-SA-2019-2160) | Nessus | Huawei Local Security Checks | high |
126254 | Ubuntu 16.04 LTS / 18.04 LTS / 18.10 / 19.04 : ImageMagick vulnerabilities (USN-4034-1) | Nessus | Ubuntu Local Security Checks | medium |
123325 | openSUSE Security Update : ImageMagick (openSUSE-2019-758) | Nessus | SuSE Local Security Checks | high |
120117 | SUSE SLED15 / SLES15 Security Update : ImageMagick (SUSE-SU-2018:2977-1) | Nessus | SuSE Local Security Checks | high |
118354 | SUSE SLES11 Security Update : ImageMagick (SUSE-SU-2018:3348-1) | Nessus | SuSE Local Security Checks | medium |
117975 | openSUSE Security Update : ImageMagick (openSUSE-2018-1108) | Nessus | SuSE Local Security Checks | high |
117935 | Ubuntu 14.04 LTS / 16.04 LTS / 18.04 LTS : imagemagick vulnerabilities (USN-3785-1) | Nessus | Ubuntu Local Security Checks | high |
117686 | openSUSE Security Update : ImageMagick (openSUSE-2018-1038) | Nessus | SuSE Local Security Checks | high |
117660 | SUSE SLED12 / SLES12 Security Update : ImageMagick (SUSE-SU-2018:2778-1) | Nessus | SuSE Local Security Checks | high |
117382 | openSUSE Security Update : GraphicsMagick (openSUSE-2018-993) | Nessus | SuSE Local Security Checks | medium |