Skip to main content

Off-by-one Error

CVE-2019-10131

Severity High
Score 7.1/10

Summary

An off-by-one read vulnerability was discovered in ImageMagick 7.x before 7.0.7-28 and ImageMagick 6.x before 6.9.9-40 in the formatIPTCfromBuffer function in coders/meta.c. A local attacker may use this flaw to read beyond the end of the buffer or to crash the program.

  • LOW
  • LOCAL
  • NONE
  • UNCHANGED
  • NONE
  • LOW
  • HIGH
  • HIGH

CWE-193 - Off-by-one Error

A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

Advisory Timeline

  • Published