CVE-2018-1180
published 2018-05-17CVE-2018-1180: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to…
PriorityP350high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
2.74%
84.6th percentile
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the AFSimple_Calculate method. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5491.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| foxit | foxit_reader | — | — |
| foxitsoftware | foxit_reader | <= 9.0.1.1049 | — |
| foxitsoftware | phantompdf | <= 9.0.1.1049 | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-16750 ImageMagick: Memory leak in the formatIPTCfromBuffer function in coders/meta.c
bugzilla·2018-09-11·CVSS 6.5
CVE-2018-16750 [MEDIUM] CVE-2018-16750 ImageMagick: Memory leak in the formatIPTCfromBuffer function in coders/meta.c
CVE-2018-16750 ImageMagick: Memory leak in the formatIPTCfromBuffer function in coders/meta.c
In ImageMagick 7.0.7-29 and earlier, a memory leak in the formatIPTCfromBuffer function in coders/meta.c was found.
Upstream issue:
https://github.com/ImageMagick/ImageMagick/issues/1118
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1627919]
---
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/33d1b9590c401d4aee666ffd10b16868a38cf705 [ImageMagick]
https://github.com/ImageMagick/ImageMagick6/commit/359331c61193138ce2b85331df25235b81499cfc [ImageMagick6]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now cl
Bugzilla
CVE-2018-16328 ImageMagick: NULL pointer dereference in CheckEventLogging function in MagickCore/log.c
bugzilla·2018-09-03·CVSS 9.8
CVE-2018-16328 [CRITICAL] CVE-2018-16328 ImageMagick: NULL pointer dereference in CheckEventLogging function in MagickCore/log.c
CVE-2018-16328 ImageMagick: NULL pointer dereference in CheckEventLogging function in MagickCore/log.c
A flaw was found in ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the CheckEventLogging function in MagickCore/log.c.
References:
https://github.com/ImageMagick/ImageMagick/issues/1224
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1624956]
---
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/107ce8577e818cf4801e5a59641cb769d645cc95
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://ac
Bugzilla
CVE-2018-14436 ImageMagick: memory leak in ReadMIFFImage in coders/miff.c
bugzilla·2018-07-30·CVSS 6.5
CVE-2018-14436 [MEDIUM] CVE-2018-14436 ImageMagick: memory leak in ReadMIFFImage in coders/miff.c
CVE-2018-14436 ImageMagick: memory leak in ReadMIFFImage in coders/miff.c
A flaw was found in ImageMagick 7.0.8-4. A memory leak in ReadMIFFImage in coders/miff.c.
References:
https://github.com/ImageMagick/ImageMagick/issues/1191
Upstream Patch:
https://github.com/ImageMagick/ImageMagick6/commit/ae3eecad2f59e27123c1a6c891be75d06fc03656
https://github.com/ImageMagick/ImageMagick/commit/4b352c0be410ad900469a079e389178f878aded8
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1609940]
---
Memory allocated in WriteMIFFImage and referenced by colormap is not released in case image depth is not an accepted value.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/
Bugzilla
CVE-2018-14434 ImageMagick: memory leak for a colormap in WriteMPCImage in coders/mpc.c
bugzilla·2018-07-30·CVSS 6.5
CVE-2018-14434 [MEDIUM] CVE-2018-14434 ImageMagick: memory leak for a colormap in WriteMPCImage in coders/mpc.c
CVE-2018-14434 ImageMagick: memory leak for a colormap in WriteMPCImage in coders/mpc.c
A flaw was found in ImageMagick 7.0.8-4. A memory leak for a colormap in WriteMPCImage in coders/mpc.c.
References:
https://github.com/ImageMagick/ImageMagick/issues/1192
Upstream Patch:
https://github.com/ImageMagick/ImageMagick/commit/98a2cceae0dceccbfe54051167c2c80be1f13c3f
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1609934]
---
Memory allocated in WriteMPCImage and referenced by colormap is not released in case image depth is not an accepted value.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now closed. Further updat
Bugzilla
CVE-2018-10804 ImageMagick: Memory leak in WriteTIFFImage
bugzilla·2018-05-11·CVSS 6.5
CVE-2018-10804 [MEDIUM] CVE-2018-10804 ImageMagick: Memory leak in WriteTIFFImage
CVE-2018-10804 ImageMagick: Memory leak in WriteTIFFImage
A flaw was found in ImageMagick version 7.0.7-28 contains a memory leak in WriteTIFFImage in coders/tiff.c.
References:
https://github.com/ImageMagick/ImageMagick/issues/1053
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1577400]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2018-10804
Bugzilla
CVE-2018-10805 ImageMagick: Memory leak in ReadYCBCRImage
bugzilla·2018-05-11·CVSS 6.5
CVE-2018-10805 [MEDIUM] CVE-2018-10805 ImageMagick: Memory leak in ReadYCBCRImage
CVE-2018-10805 ImageMagick: Memory leak in ReadYCBCRImage
A flaw was found in ImageMagick version 7.0.7-28 contains a memory leak in ReadYCBCRImage in coders/ycbcr.c.
References:
https://github.com/ImageMagick/ImageMagick/issues/1054
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1577400]
---
Doesn't look like it's leaking canvas_image but definitely leaking quantum_info.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2018-10805
Bugzilla
CVE-2018-10177 ImageMagick: Infinite loop in coders/png.c:ReadOneMNGImage() allows attackers to cause a denial of service via crafted MNG file
bugzilla·2018-04-26·CVSS 6.5
CVE-2018-10177 [MEDIUM] CVE-2018-10177 ImageMagick: Infinite loop in coders/png.c:ReadOneMNGImage() allows attackers to cause a denial of service via crafted MNG file
CVE-2018-10177 ImageMagick: Infinite loop in coders/png.c:ReadOneMNGImage() allows attackers to cause a denial of service via crafted MNG file
ImageMagick through version 7.0.7-28 is vulnerable to an infinite loop in coders/png.c:ReadOneMNGImage(). An attacker could exploit this to cause a denial of service via crafted MNG file.
References:
https://github.com/ImageMagick/ImageMagick/issues/1095
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1572045]
---
Upstream commit:
https://github.com/ImageMagick/ImageMagick6/commit/9eda4b36a8695e4a0cd27bea28b9c173c68a01ec
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now clo
Bugzilla
CVE-2018-9133 ImageMagick: excessive iteration in the DecodeLabImage and EncodeLabImage functions in coders/tiff.c
bugzilla·2018-04-05·CVSS 6.5
CVE-2018-9133 [MEDIUM] CVE-2018-9133 ImageMagick: excessive iteration in the DecodeLabImage and EncodeLabImage functions in coders/tiff.c
CVE-2018-9133 ImageMagick: excessive iteration in the DecodeLabImage and EncodeLabImage functions in coders/tiff.c
A flaw was found in ImageMagick 7.0.7-26 Q16. An excessive iteration in the DecodeLabImage and EncodeLabImage functions (coders/tiff.c), which results in a hang (tens of minutes) with a tiny PoC file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tiff file.
References:
https://github.com/ImageMagick/ImageMagick/issues/1072
Patch:
https://github.com/ImageMagick/ImageMagick/commit/089fca04e0130549fa15f48ace3f56e30a06049a
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1561740]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180
2018-05-17
Published