In ImageMagick 7.0.7-29 and earlier, a missing NULL check in ReadOneJNGImage in coders/png.c allows an attacker to cause a denial of service (WriteBlob assertion failure and application exit) via a crafted file.
https://github.com/ImageMagick/ImageMagick/issues/1119
https://github.com/ImageMagick/ImageMagick6/commit/1007b98f8795ad4bea6bc5f68a32d83e982fdae4
https://lists.debian.org/debian-lts-announce/2018/10/msg00002.html
https://lists.debian.org/debian-lts-announce/2020/09/msg00007.html
Source: MITRE
Published: 2018-09-09
Updated: 2020-09-08
Type: CWE-617
Base Score: 4.3
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P
Impact Score: 2.9
Exploitability Score: 8.6
Severity: MEDIUM
Base Score: 6.5
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Impact Score: 3.6
Exploitability Score: 2.8
Severity: MEDIUM
OR
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* versions up to 7.0.7-29 (inclusive)
OR
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
143991 | NewStart CGSL CORE 5.05 / MAIN 5.05 : ImageMagick Multiple Vulnerabilities (NS-SA-2020-0119) | Nessus | NewStart CGSL Local Security Checks | high |
143964 | NewStart CGSL CORE 5.04 / MAIN 5.04 : ImageMagick Multiple Vulnerabilities (NS-SA-2020-0079) | Nessus | NewStart CGSL Local Security Checks | high |
142319 | EulerOS 2.0 SP2 : ImageMagick (EulerOS-SA-2020-2349) | Nessus | Huawei Local Security Checks | medium |
141987 | Amazon Linux 2 : ImageMagick (ALAS-2020-1497) | Nessus | Amazon Linux Local Security Checks | high |
140857 | EulerOS 2.0 SP3 : ImageMagick (EulerOS-SA-2020-2090) | Nessus | Huawei Local Security Checks | medium |
140297 | Debian DLA-2366-1 : imagemagick security update | Nessus | Debian Local Security Checks | high |
139136 | EulerOS 2.0 SP8 : ImageMagick (EulerOS-SA-2020-1806) | Nessus | Huawei Local Security Checks | medium |
138633 | Amazon Linux AMI : php-pecl-imagick (ALAS-2020-1391) | Nessus | Amazon Linux Local Security Checks | high |
135797 | Scientific Linux Security Update : ImageMagick on SL7.x x86_64 (20200407) | Nessus | Scientific Linux Local Security Checks | high |
135354 | CentOS 7 : ImageMagick / autotrace / emacs / inkscape (CESA-2020:1180) | Nessus | CentOS Local Security Checks | high |
135041 | RHEL 7 : ImageMagick (RHSA-2020:1180) | Nessus | Red Hat Local Security Checks | high |
122248 | ImageMagick < 7.0.8-25 Multiple Vulnerabilities | Nessus | Windows | medium |
118354 | SUSE SLES11 Security Update : ImageMagick (SUSE-SU-2018:3348-1) | Nessus | SuSE Local Security Checks | medium |
118192 | openSUSE Security Update : ImageMagick (openSUSE-2018-1181) | Nessus | SuSE Local Security Checks | medium |
118078 | SUSE SLED12 / SLES12 Security Update : ImageMagick (SUSE-SU-2018:3095-1) | Nessus | SuSE Local Security Checks | medium |
117935 | Ubuntu 14.04 LTS / 16.04 LTS / 18.04 LTS : imagemagick vulnerabilities (USN-3785-1) | Nessus | Ubuntu Local Security Checks | high |
117907 | Debian DLA-1530-1 : imagemagick security update | Nessus | Debian Local Security Checks | medium |
117693 | openSUSE Security Update : GraphicsMagick (openSUSE-2018-1045) | Nessus | SuSE Local Security Checks | medium |