VDB
CVE-2019-10649
CVE-2019-10649
PUBLISHED
Es existieren mehrere Schwachstellen in ImageMagick. Diese Schwachstellen existieren aufgrund eines heap-basierten Buffer over-read in der Funktion WriteTIFFImage und eines Memory Leaks in SVGKeyValuePairs of coders/svg.c. Ein entfernter anonymer Angreifer kann diese Schwachstellen ausnutzen um einen Denial of Service Zustand zu erzeugen. Zur erfolgreichen Ausnutzung dieser Schwachstellen muss der Angreifer den Benutzer dazu bringen eine modifizierte Datei zu öffnen.
EPSS 0.35% · 57.5th percentile
Risk Scores
EPSS Score
0.35%
57.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Avaya | Avaya Aura Communication Manager | |
| Avaya | Avaya Aura Application Enablement Services | |
| Avaya | Avaya Aura Session Manager | |
| Debian | Debian Linux | |
| Avaya | Avaya Web License Manager | |
| Avaya | Avaya Aura System Manager | |
| Ubuntu | Ubuntu Linux | |
| Open Source | Open Source ImageMagick 7.0.8-36 Q16 | |
| Red Hat | Red Hat Enterprise Linux | |
| SUSE | SUSE Linux | |
| Amazon | Amazon Linux 2 |
Exploit Intelligence
- https://github.com/ImageMagick/ImageMagick/issues/1533 (nist-nvd)
- 107645 (circl)
- USN-4034-1 (circl)
- DSA-4712 (circl)
Timeline
- Mar 30, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2019/wid-sec-w-2023-2143.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-2143 advisory
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10650 advisory
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10649 advisory
- https://www.suse.com/support/update/announcement/2019/suse-su-20191019-1.html advisory
- https://www.suse.com/support/update/announcement/2019/suse-su-20191033-1.html advisory
- https://www.suse.com/support/update/announcement/2019/suse-su-20191033-2.html advisory
- https://www.debian.org/security/2019/dsa-4436 advisory
- https://www.suse.com/support/update/announcement/2019/suse-su-201914043-1.html advisory
- https://usn.ubuntu.com/4034-1/ advisory
- https://access.redhat.com/errata/RHSA-2020:1180 advisory
- https://downloads.avaya.com/css/P8/documents/101065660 advisory
- https://www.debian.org/security/2020/dsa-4712 advisory
- https://alas.aws.amazon.com/ALAS-2023-1815.html advisory
- https://alas.aws.amazon.com/ALAS-2023-1814.html advisory
- https://alas.aws.amazon.com/ALAS-2023-1813.html advisory
- https://alas.aws.amazon.com/ALAS-2023-1812.html advisory
- https://alas.aws.amazon.com/ALAS-2023-1811.html advisory
- https://alas.aws.amazon.com/ALAS-2023-1810.html advisory
- https://alas.aws.amazon.com/ALAS-2024-1926.html advisory
…and 1 more