CVE-2018-16328NULL Pointer Dereference in Imagemagick

Severity
9.8CRITICALNVD
GHSA7.5
EPSS
0.2%
top 60.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 1
Latest updateMay 14

Description

In ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the CheckEventLogging function in MagickCore/log.c.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

debiandebian/imagemagick< imagemagick 8:6.9.10.8+dfsg-1 (bookworm)
Debianimagemagick/imagemagick< 8:6.9.10.8+dfsg-1+3
PyPIrpyc_project/rpyc4.1.04.1.1

🔴Vulnerability Details

3
GHSA
GHSA-fw3w-492m-rr7g: In ImageMagick before 72022-05-14
GHSA
Dynamic modification of RPyC service due to missing security check2021-02-17
OSV
CVE-2018-16328: In ImageMagick before 72018-09-01

📋Vendor Advisories

2
Red Hat
ImageMagick: NULL pointer dereference in CheckEventLogging function in MagickCore/log.c2018-07-23
Debian
CVE-2018-16328: imagemagick - In ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the CheckEve...2018

💬Community

2
Bugzilla
CVE-2018-16328 ImageMagick: NULL pointer dereference in CheckEventLogging function in MagickCore/log.c2018-09-03
Bugzilla
CVE-2018-16328 ImageMagick: NULL pointer dereference in CheckEventLogging function in MagickCore/log.c [fedora-all]2018-09-03