CVE-2017-1180
published 2017-04-05CVE-2017-1180: The IBM TRIRIGA Document Manager contains a vulnerability that could allow an authenticated user to execute actions they did not have access to. IBM Reference…
PriorityP428medium5.3CVSS 3.0
AVNACHPRLUINSUCNIHAN
EPSS
0.72%
49.7th percentile
The IBM TRIRIGA Document Manager contains a vulnerability that could allow an authenticated user to execute actions they did not have access to. IBM Reference #: 2001084.
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
| ibm | tririga_application_platform | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Bugzilla
CVE-2017-18273 ImageMagick: infinite loop ReadTXTImage in function in coders/txt.c
bugzilla·2018-05-22·CVSS 6.5
CVE-2017-18273 [MEDIUM] CVE-2017-18273 ImageMagick: infinite loop ReadTXTImage in function in coders/txt.c
CVE-2017-18273 ImageMagick: infinite loop ReadTXTImage in function in coders/txt.c
In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadTXTImage in coders/txt.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted image file that is mishandled in a GetImageIndexInList call.
References:
https://github.com/ImageMagick/ImageMagick/issues/910
Patch:
https://github.com/ImageMagick/ImageMagick/commit/d95991f24d27dbc335dfa7c0523c886ab9329e9e
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1581487]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bu
Bugzilla
CVE-2017-18271 ImageMagick: infinite loop in ReadMIFFImage function in coders/miff.c
bugzilla·2018-05-22·CVSS 6.5
CVE-2017-18271 [MEDIUM] CVE-2017-18271 ImageMagick: infinite loop in ReadMIFFImage function in coders/miff.c
CVE-2017-18271 ImageMagick: infinite loop in ReadMIFFImage function in coders/miff.c
A flaw was found in ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadMIFFImage in coders/miff.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted MIFF image file.
References:
https://github.com/ImageMagick/ImageMagick/issues/911
Patch:
https://github.com/ImageMagick/ImageMagick/commit/7523250e2664028aa1d8f02d2d7ae49c769a851e
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1581487]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now closed. Furthe
Bugzilla
CVE-2017-18252 ImageMagick: assertion failure in MogrifyImageList function in MagickWand/mogrify.c
bugzilla·2018-03-28·CVSS 6.5
CVE-2017-18252 [MEDIUM] CVE-2017-18252 ImageMagick: assertion failure in MogrifyImageList function in MagickWand/mogrify.c
CVE-2017-18252 ImageMagick: assertion failure in MogrifyImageList function in MagickWand/mogrify.c
An issue was discovered in ImageMagick 7.0.7. The MogrifyImageList function in MagickWand/mogrify.c allows attackers to cause a denial of service (assertion failure and application exit in ReplaceImageInList) via a crafted file.
References:
https://github.com/ImageMagick/ImageMagick/issues/802
Patches:
https://github.com/ImageMagick/ImageMagick/commit/bb04ccb34fd45e9c3020786857fb79b09f44d7db
https://github.com/ImageMagick/ImageMagick/commit/12f34b60564de1cbec08e23e2413dab5b64daeb7
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1561740]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 h
Bugzilla
CVE-2017-18254 ImageMagick: memory leak in WriteGIFImage function in coders/gif.c
bugzilla·2018-03-28·CVSS 6.5
CVE-2017-18254 [MEDIUM] CVE-2017-18254 ImageMagick: memory leak in WriteGIFImage function in coders/gif.c
CVE-2017-18254 ImageMagick: memory leak in WriteGIFImage function in coders/gif.c
An issue was discovered in ImageMagick 7.0.7. A memory leak vulnerability was found in the function WriteGIFImage in coders/gif.c, which allow remote attackers to cause a denial of service via a crafted file.
References:
https://github.com/ImageMagick/ImageMagick/issues/808
Patches:
https://github.com/ImageMagick/ImageMagick/commit/24d5699753170c141b46816284430516c2d48fed
https://github.com/ImageMagick/ImageMagick/commit/53ea13989003cdb4955024f95b4a0158a2e871c6
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1561740]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-
Bugzilla
CVE-2017-18251 ImageMagick: memory leak in ReadPCDImage function in coders/pcd.c
bugzilla·2018-03-28·CVSS 6.5
CVE-2017-18251 [MEDIUM] CVE-2017-18251 ImageMagick: memory leak in ReadPCDImage function in coders/pcd.c
CVE-2017-18251 ImageMagick: memory leak in ReadPCDImage function in coders/pcd.c
An issue was discovered in ImageMagick 7.0.7. A memory leak vulnerability was found in the function ReadPCDImage in coders/pcd.c, which allow remote attackers to cause a denial of service via a crafted file.
References:
https://github.com/ImageMagick/ImageMagick/issues/809
Patches:
https://github.com/ImageMagick/ImageMagick/commit/12a43437fec6f9245327636dc2730863bb9fdd8b
https://github.com/ImageMagick/ImageMagick/commit/99718b41102f26f802311045e882aa947ef2941b
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1561740]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-20
http://www.ibm.com/support/docview.wss?uid=swg22001084http://www.securityfocus.com/bid/97273https://exchange.xforce.ibmcloud.com/vulnerabilities/123432?cm_mc_uid=06394756914614889387221&cm_mc_sid_50200000=1491939602http://www.ibm.com/support/docview.wss?uid=swg22001084http://www.securityfocus.com/bid/97273
2017-04-05
Published