ImageMagick before 7.0.8-55 has a use-after-free in DestroyStringInfo in MagickCore/string.c because the error manager is mishandled in coders/jpeg.c.
2019-10-14T02:15:10.703
2024-11-21T04:32:29.170
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | imagemagick | imagemagick | < 6.9.10-55 | Yes |
Application | imagemagick | imagemagick | < 7.0.8-55 | Yes |