8.8
CVE-2012-0247
- EPSS 3.82%
- Veröffentlicht 05.06.2012 22:55:06
- Zuletzt bearbeitet 16.06.2026 23:36:58
- Erkennungen
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset and count values in the ResolutionUnit tag in the EXIF IFD0 of an image.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Imagemagick ≫ Imagemagick Version <= 6.7.5-7
Debian ≫ Debian Linux Version 6.0
Debian ≫ Debian Linux Version 7.0
Canonical ≫ Ubuntu Linux Version 10.04
Canonical ≫ Ubuntu Linux Version 11.04
Canonical ≫ Ubuntu Linux Version 11.10
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition esm
Redhat ≫ Enterprise Linux Desktop Version 5.0
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Eus Version 6.2
Redhat ≫ Enterprise Linux Server Version 5.0
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Server Aus Version 6.2
Redhat ≫ Enterprise Linux Server Eus Version 6.2
Redhat ≫ Enterprise Linux Workstation Version 5.0
Redhat ≫ Enterprise Linux Workstation Version 6.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.82% | 0.887 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| NIST | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://rhn.redhat.com/errata/RHSA-2012-0544.html
http://secunia.com/advisories/49063
http://rhn.redhat.com/errata/RHSA-2012-0545.html
http://secunia.com/advisories/47926
http://secunia.com/advisories/48247
http://secunia.com/advisories/48259
http://secunia.com/advisories/49043
http://secunia.com/advisories/49068
http://ubuntu.com/usn/usn-1435-1
http://www.cert.fi/en/reports/2012/vulnerability595210.html
http://www.debian.org/security/2012/dsa-2427
http://www.gentoo.org/security/en/glsa/glsa-201203-09.xml
http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=20286
http://www.osvdb.org/79003
http://www.securitytracker.com/id?1027032