Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
ImageMagick before 7.0.5-2 and GraphicsMagick before 1.3.24 use uninitialized memory in the RLE decoder, allowing an attacker to leak sensitive information from process memory space, as demonstrated by remote attacks against ImageMagick code in a long-running server process that converts image data on behalf of multiple users. This is caused by a missing initialization step in the ReadRLEImage function in coders/rle.c.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ImageMagick 安全漏洞
Vulnerability Description
ImageMagick是美国ImageMagick Studio公司的一套开源的图象处理软件。该软件可读取、转换、写入多种格式的图片。 ImageMagick 7.0.5-2之前的版本中存在安全漏洞,该漏洞源于coders/rle.c文件的‘ReadRLEImage’函数没有执行初始化步骤。攻击者可利用该漏洞获取进程空间内存中的敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A