Exploit/Advisories

Published on March 26th, 2019 📆 | 7181 Views ⚑

0

ImageMagick CVE-2019-9956 Stack Buffer Overflow Vulnerability


iSpeech

ImageMagick is prone to a stack-based buffer-overflow vulnerability.

Attackers can exploit this issue to run arbitrary code within the context of the affected application. Failed exploit attempts may result in denial-of-service conditions.
ImageMagick 7.0.8-35 Q16 is vulnerable; other versions may also be affected.

Information

Bugtraq ID: 107546

Class: Failure to Handle Exceptional Conditions

CVE: CVE-2019-9956

Remote: Yes





Local: No

Published: Mar 23 2019 12:00AM

Updated: Mar 23 2019 12:00AM

Credit: galycannon

Vulnerable: ImageMagick ImageMagick 7.0.8-35 Q16

Not Vulnerable:

Exploit

The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.

(function(d, s, id) {
var js, fjs = d.getElementsByTagName(s)[0];
if (d.getElementById(id)) return;
js = d.createElement(s); js.id = id;
js.src = "http://connect.facebook.net/en_US/sdk.js#xfbml=1&version=v2.8&appId=409115965821184";
fjs.parentNode.insertBefore(js, fjs);
}(document, 'script', 'facebook-jssdk'));

Tagged with:



Comments are closed.