MEDIUM 5.1
GHSA-8793-7xv6-82cf
ImageMagick has an Out-of-bounds Write via InterpretImageFilename
Details
Due to an incorrect return value on certain platforms a pointer is incremented past the end of a buffer that is on the stack and that could result in an out of bounds write.
``` ================================================================= ==48558==ERROR: AddressSanitizer: stack-buffer-overflow on address 0x00016b9b7490 at pc 0x0001046d48ac bp 0x00016b9b31d0 sp 0x00016b9b31c8 WRITE of size 1 at 0x00016b9b7490 thread T0 ```
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet / Magick.NET-Q16-AnyCPU
Introduced in:
0 Fixed in: 14.11.1 Fix
dotnet add package Magick.NET-Q16-AnyCPU --version 14.11.1 NuGet / Magick.NET-Q16-HDRI-AnyCPU
Introduced in:
0 Fixed in: 14.11.1 Fix
dotnet add package Magick.NET-Q16-HDRI-AnyCPU --version 14.11.1 NuGet / Magick.NET-Q16-HDRI-OpenMP-arm64
Introduced in:
0 Fixed in: 14.11.1 Fix
dotnet add package Magick.NET-Q16-HDRI-OpenMP-arm64 --version 14.11.1 NuGet / Magick.NET-Q16-HDRI-arm64
Introduced in:
0 Fixed in: 14.11.1 Fix
dotnet add package Magick.NET-Q16-HDRI-arm64 --version 14.11.1 NuGet / Magick.NET-Q16-HDRI-x64
Introduced in:
0 Fixed in: 14.11.1 Fix
dotnet add package Magick.NET-Q16-HDRI-x64 --version 14.11.1 NuGet / Magick.NET-Q16-HDRI-x86
Introduced in:
0 Fixed in: 14.11.1 Fix
dotnet add package Magick.NET-Q16-HDRI-x86 --version 14.11.1 NuGet / Magick.NET-Q16-OpenMP-arm64
Introduced in:
0 Fixed in: 14.11.1 Fix
dotnet add package Magick.NET-Q16-OpenMP-arm64 --version 14.11.1 NuGet / Magick.NET-Q16-OpenMP-x64
Introduced in:
0 Fixed in: 14.11.1 Fix
dotnet add package Magick.NET-Q16-OpenMP-x64 --version 14.11.1 NuGet / Magick.NET-Q16-OpenMP-x86
Introduced in:
0 Fixed in: 14.11.1 Fix
dotnet add package Magick.NET-Q16-OpenMP-x86 --version 14.11.1 NuGet / Magick.NET-Q16-arm64
Introduced in:
0 Fixed in: 14.11.1 Fix
dotnet add package Magick.NET-Q16-arm64 --version 14.11.1 NuGet / Magick.NET-Q16-x64
Introduced in:
0 Fixed in: 14.11.1 Fix
dotnet add package Magick.NET-Q16-x64 --version 14.11.1 NuGet / Magick.NET-Q16-x86
Introduced in:
0 Fixed in: 14.11.1 Fix
dotnet add package Magick.NET-Q16-x86 --version 14.11.1 NuGet / Magick.NET-Q8-AnyCPU
Introduced in:
0 Fixed in: 14.11.1 Fix
dotnet add package Magick.NET-Q8-AnyCPU --version 14.11.1 NuGet / Magick.NET-Q8-OpenMP-x64
Introduced in:
0 Fixed in: 14.11.1 Fix
dotnet add package Magick.NET-Q8-OpenMP-x64 --version 14.11.1 NuGet / Magick.NET-Q8-arm64
Introduced in:
0 Fixed in: 14.11.1 Fix
dotnet add package Magick.NET-Q8-arm64 --version 14.11.1 NuGet / Magick.NET-Q8-x64
Introduced in:
0 Fixed in: 14.11.1 Fix
dotnet add package Magick.NET-Q8-x64 --version 14.11.1 NuGet / Magick.NET-Q8-x86
Introduced in:
0 Fixed in: 14.11.1 Fix
dotnet add package Magick.NET-Q8-x86 --version 14.11.1