V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2018-6799
AST
High

The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before 1.3.28 allows remote attackers to cause a denial of service…

CVSS
8.8
High
EPSS
0.03
p83
Published
2018-01-01
Updated
2018-01-01
Description

The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before 1.3.28 allows remote attackers to cause a denial of service (heap overwrite) or possibly have unspecified other impact via a crafted image file, because a pixel staging area is not used.

Tags · CWE
RCEPre-auth
CWE-119
CAPEC-8
CAPEC-9
CAPEC-10
CAPEC-14
CAPEC-24
CAPEC-42
CAPEC-44
CAPEC-45
CAPEC-46
CAPEC-47
CAPEC-100
CAPEC-123
Affected products
GraphicsmagickGraphicsmagickGraphicsmagickGraphicsmagickGraphicsmagickGraphicsmagickGraphicsmagickGraphicsmagickGraphicsmagickGraphicsmagickGraphicsmagickGraphicsmagickGraphicsmagickGraphicsmagickGraphicsmagickGraphicsmagickGraphicsmagickGraphicsmagickGraphicsmagickGraphicsmagick
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Timeline
2018-01-01
Published
2018-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: R
Required (R)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.026 · p83
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
graphicsmagickTracked
graphicsmagickTracked
graphicsmagickTracked
graphicsmagickTracked
graphicsmagickTracked
graphicsmagickTracked
graphicsmagickTracked
graphicsmagickTracked
graphicsmagickTracked
graphicsmagickTracked
graphicsmagickTracked
graphicsmagickTracked
graphicsmagickTracked
graphicsmagickTracked
graphicsmagickTracked
graphicsmagickTracked
graphicsmagickTracked
graphicsmagickTracked
graphicsmagickTracked
graphicsmagickTracked
Showing first 20 of 24
Source databases
AST
DEB
CVE
UBU