Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4537
HistoryJul 05, 2017 - 10:26 p.m.

Heap-based Buffer Over-read

2017-07-0522:26:11
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

EPSS

0.01

Percentile

83.4%

ImageMagick is vulnerable to heap-based over-reads. The GenNextToken function in token.c allows attackers to read sensitive information from memory and possibly other attacks. It can be exploited through a mishandled SVG document in the GetUserSpaceCoordinateValue function.