ImageMagick CVE-2018-8960 Heap Buffer Overflow Vulnerability

随机文章
原文链接:www.securityfocus.com

ImageMagick CVE-2018-8960 堆缓冲区溢出漏洞,暂时没有利用的 PoC,不过可以造成 dos 攻击。

别轻视这样的漏洞, ImageMagick 作为处理图片的通用组件,各大厂商的使用不在少数!

ImageMagick is prone to a heap-based buffer-overflow vulnerability.

An attacker can exploit this issue to cause a denial-of-service condition. Due to the nature of this issue, code execution may be possible but this has not been confirmed.

ImageMagick 7.0.7-26 Q16 is vulnerable; other versions may also be affected.

可以参考这里 heap-buffer-overflow in 7.0.7-26