CVE-2019-10131
Public on 2019-04-30
Modified on 2020-10-22
Description
An off-by-one read vulnerability was discovered in ImageMagick in the formatIPTCfromBuffer function in coders/meta.c. A local attacker may use this flaw to read beyond the end of the buffer or to crash the program.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
Amazon Linux 1 | ImageMagick | 2024-03-19 | ALAS-2024-1926 | Fixed |
Amazon Linux 2 - Core | ImageMagick | 2020-10-27 | ALAS2-2020-1497 | Fixed |
Amazon Linux 2 - Core | ImageMagick | 2024-01-22 | ALAS2-2024-2432 | Fixed |
Amazon Linux 1 | php-pecl-imagick | 2020-06-26 | ALAS-2020-1391 | Fixed |
Amazon Linux 1 | php54-pecl-imagick | 2023-09-07 | ALAS-2023-1810 | Fixed |
Amazon Linux 1 | php55-pecl-imagick | 2023-09-07 | ALAS-2023-1812 | Fixed |
Amazon Linux 1 | php56-pecl-imagick | 2023-09-07 | ALAS-2023-1811 | Fixed |
Amazon Linux 1 | php70-pecl-imagick | 2023-09-07 | ALAS-2023-1813 | Fixed |
Amazon Linux 1 | php71-pecl-imagick | 2023-09-07 | ALAS-2023-1814 | Fixed |
Amazon Linux 1 | php72-pecl-imagick | 2023-09-07 | ALAS-2023-1815 | Fixed |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 6.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
NVD | CVSSv2 | 3.6 | AV:L/AC:L/Au:N/C:P/I:N/A:P |
NVD | CVSSv3 | 7.1 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |