CVE-2018-16323
medium · 6.5ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If the affected code is used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data.
6.5
CVSS
49.3%
EPSS (exploit prob.)
99th
EPSS percentile
2018-09-01
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Weaknesses
CWE-200
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| imagemagick | imagemagick | < 6.9.10-9 |
| imagemagick | imagemagick | >= 7.0.0-0, < 7.0.8-9 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 18.10 |
| canonical | ubuntu_linux | 19.04 |
Check a specific version with /api/v1/cve/match.
References
- https://github.com/ImageMagick/ImageMagick/commit/216d117f05bff87b9dc4db55a1b1fadb38bcb786
- https://usn.ubuntu.com/3785-1/
- https://usn.ubuntu.com/4034-1/
- https://www.exploit-db.com/exploits/45890/
- https://github.com/ImageMagick/ImageMagick/commit/216d117f05bff87b9dc4db55a1b1fadb38bcb786
- https://usn.ubuntu.com/3785-1/
- https://usn.ubuntu.com/4034-1/
- https://www.exploit-db.com/exploits/45890/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-16323