CVE-2012-0247
published 2012-06-05CVE-2012-0247: ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset…
PriorityP344high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
3.82%
88.9th percentile
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset and count values in the ResolutionUnit tag in the EXIF IFD0 of an image.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | imagemagick | < imagemagick 8:6.6.9.7-7 (bookworm) | imagemagick 8:6.6.9.7-7 (bookworm) |
| debian | imagemagick | < imagemagick 8:6.6.9.7-6 (bookworm) | imagemagick 8:6.6.9.7-6 (bookworm) |
| imagemagick | imagemagick | <= 6.7.5-7 | — |
| imagemagick | imagemagick | <= 6.7.5 | — |
| imagemagick | imagemagick | >= 0 < 8:6.6.9.7-6 | 8:6.6.9.7-6 |
| imagemagick | imagemagick | >= 0 < 8:6.6.9.7-7 | 8:6.6.9.7-7 |
| imagemagick | imagemagick | >= 0 < 8:6.6.9.7-6 | 8:6.6.9.7-6 |
| imagemagick | imagemagick | >= 0 < 8:6.6.9.7-7 | 8:6.6.9.7-7 |
| imagemagick | imagemagick | >= 0 < 8:6.6.9.7-6 | 8:6.6.9.7-6 |
| imagemagick | imagemagick | >= 0 < 8:6.6.9.7-7 | 8:6.6.9.7-7 |
| imagemagick | imagemagick | >= 0 < 8:6.6.9.7-6 | 8:6.6.9.7-6 |
| imagemagick | imagemagick | >= 0 < 8:6.6.9.7-7 | 8:6.6.9.7-7 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6j5v-g8wm-9r98: Multiple integer overflows in (1) magick/profile
ghsa_unreviewed·2022-05-13·CVSS 8.8
CVE-2012-1185 [HIGH] CWE-190 GHSA-6j5v-g8wm-9r98: Multiple integer overflows in (1) magick/profile
Multiple integer overflows in (1) magick/profile.c or (2) magick/property.c in ImageMagick 6.7.5 and earlier allow remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset value in the ResolutionUnit tag in the EXIF IFD0 of an image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0247.
GHSA
GHSA-v335-7263-364v: ImageMagick 6
ghsa_unreviewed·2022-05-04
CVE-2012-0247 [HIGH] CWE-20 GHSA-v335-7263-364v: ImageMagick 6
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset and count values in the ResolutionUnit tag in the EXIF IFD0 of an image.
OSV
CVE-2012-0247: ImageMagick 6
osv·2012-06-05·CVSS 8.8
CVE-2012-0247 [HIGH] CVE-2012-0247: ImageMagick 6
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset and count values in the ResolutionUnit tag in the EXIF IFD0 of an image.
OSV
CVE-2012-1185: Multiple integer overflows in (1) magick/profile
osv·2012-06-05·CVSS 8.8
CVE-2012-1185 [HIGH] CVE-2012-1185: Multiple integer overflows in (1) magick/profile
Multiple integer overflows in (1) magick/profile.c or (2) magick/property.c in ImageMagick 6.7.5 and earlier allow remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset value in the ResolutionUnit tag in the EXIF IFD0 of an image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0247.
Red Hat
Keystone: denial of service through invalid token requests
vendor_redhat·2013-02-05·CVSS 5.0
CVE-2013-0247 [MEDIUM] Keystone: denial of service through invalid token requests
Keystone: denial of service through invalid token requests
OpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and earlier, and Grizzly grizzly-2 and earlier allows remote attackers to cause a denial of service (disk consumption) via many invalid token requests that trigger excessive generation of log entries.
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2012-05-01·CVSS 8.8
CVE-2012-0247 [HIGH] ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: ImageMagick could be made to crash or run programs as your login if it
opened a specially crafted file.
Joonas Kuorilehto and Aleksis Kauppinen discovered that ImageMagick
incorrectly handled certain ResolutionUnit tags. If a user or automated
system using ImageMagick were tricked into opening a specially crafted
image, an attacker could exploit this to cause a denial of service or
possibly execute code with the privileges of the user invoking the program.
(CVE-2012-0247, CVE-2012-1185)
Joonas Kuorilehto and Aleksis Kauppinen discovered that ImageMagick
incorrectly handled certain IFD structures. If a user or automated
system using ImageMagick were tricked into opening a specially crafted
image, an attacker could exploit this to cause a denial
Red Hat
ImageMagick: Incorrect fix for CVE-2012-0247
vendor_redhat·2012-03-19·CVSS 8.8
CVE-2012-1185 [HIGH] ImageMagick: Incorrect fix for CVE-2012-0247
ImageMagick: Incorrect fix for CVE-2012-0247
Multiple integer overflows in (1) magick/profile.c or (2) magick/property.c in ImageMagick 6.7.5 and earlier allow remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset value in the ResolutionUnit tag in the EXIF IFD0 of an image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0247.
Statement: Not vulnerable. This issue did not affect the versions of ImageMagick as shipped with Red Hat Enterprise Linux 5 and 6 as they did not backport the insufficient patch for CVE-2012-0247.
Package: ImageMagick (Red Hat Enterprise Linux 5) - Not affected
Package: ImageMagick (Red Hat Enterprise Linux 6) - Not affected
Red Hat
ImageMagick: invalid validation of images denial of service
vendor_redhat·2012-02-03·CVSS 8.8
CVE-2012-0247 [HIGH] ImageMagick: invalid validation of images denial of service
ImageMagick: invalid validation of images denial of service
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset and count values in the ResolutionUnit tag in the EXIF IFD0 of an image.
Package: ImageMagick (Red Hat Enterprise Linux 4) - Not affected
Debian
CVE-2012-1185: imagemagick - Multiple integer overflows in (1) magick/profile.c or (2) magick/property.c in I...
vendor_debian·2012·CVSS 8.8
CVE-2012-1185 [HIGH] CVE-2012-1185: imagemagick - Multiple integer overflows in (1) magick/profile.c or (2) magick/property.c in I...
Multiple integer overflows in (1) magick/profile.c or (2) magick/property.c in ImageMagick 6.7.5 and earlier allow remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset value in the ResolutionUnit tag in the EXIF IFD0 of an image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0247.
Scope: local
bookworm: resolved (fixed in 8:6.6.9.7-7)
bullseye: resolved (fixed in 8:6.6.9.7-7)
forky: resolved (fixed in 8:6.6.9.7-7)
sid: resolved (fixed in 8:6.6.9.7-7)
trixie: resolved (fixed in 8:6.6.9.7-7)
Debian
CVE-2012-0247: imagemagick - ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of ser...
vendor_debian·2012·CVSS 8.8
CVE-2012-0247 [HIGH] CVE-2012-0247: imagemagick - ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of ser...
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset and count values in the ResolutionUnit tag in the EXIF IFD0 of an image.
Scope: local
bookworm: resolved (fixed in 8:6.6.9.7-6)
bullseye: resolved (fixed in 8:6.6.9.7-6)
forky: resolved (fixed in 8:6.6.9.7-6)
sid: resolved (fixed in 8:6.6.9.7-6)
trixie: resolved (fixed in 8:6.6.9.7-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-1185: ImageMagick: Incorrect fix for CVE-2012-0247
bugzilla·2012-03-19·CVSS 8.8
CVE-2012-1185 [HIGH] CVE-2012-1185: ImageMagick: Incorrect fix for CVE-2012-0247
CVE-2012-1185: ImageMagick: Incorrect fix for CVE-2012-0247
The original fix for CVE-2012-0247 was found to be insufficient.
The original fix for CVE-2012-0247 failed to check for the possibility of an integer overflow when computing the sum of "number_bytes" and "offset". This resulted in a wrap around into a value smaller than "length", making original CVE-2012-0247 introduced "length" check still to be possible to bypass, leading to memory corruption.
Relevant upstream patches:
[1] http://trac.imagemagick.org/changeset/6998/ImageMagick/branches/ImageMagick-6.7.5/magick/profile.c
[2] http://trac.imagemagick.org/changeset/6998/ImageMagick/branches/ImageMagick-6.7.5/magick/property.c
Discussion:
A CVE identifier of CVE-2012-1185 has been assigned to this issue.
---
Is upstream autho
Bugzilla
CVE-2012-0247 CVE-2012-0248 ImageMagick: invalid validation of images denial of service [fedora-all]
bugzilla·2012-02-24·CVSS 8.8
CVE-2012-0247 [HIGH] CVE-2012-0247 CVE-2012-0248 ImageMagick: invalid validation of images denial of service [fedora-all]
CVE-2012-0247 CVE-2012-0248 ImageMagick: invalid validation of images denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/up
Bugzilla
CVE-2012-0247 CVE-2012-0248 ImageMagick: invalid validation of images denial of service [fedora-all]
bugzilla·2012-02-23·CVSS 8.8
CVE-2012-0247 [HIGH] CVE-2012-0247 CVE-2012-0248 ImageMagick: invalid validation of images denial of service [fedora-all]
CVE-2012-0247 CVE-2012-0248 ImageMagick: invalid validation of images denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/up
Bugzilla
CVE-2012-0247 CVE-2012-0248 ImageMagick: invalid validation of images denial of service
bugzilla·2012-02-10·CVSS 8.8
CVE-2012-0247 [HIGH] CVE-2012-0247 CVE-2012-0248 ImageMagick: invalid validation of images denial of service
CVE-2012-0247 CVE-2012-0248 ImageMagick: invalid validation of images denial of service
Two input validation and denial of service flaws were reported [1],[2] in ImageMagick:
[CVE-2012-0247] When parsing a maliciously crafted image with incorrect offset and count in the ResolutionUnit tag in EXIF IFD0, ImageMagick copies two bytes into an invalid address.
[CVE-2012-0248] When parsing a maliciously crafted image with an IFD whose all IOP tags' value offsets point to the beginning of the IFD itself. As a result, ImageMagick parses the IFD structure indefinitely, causing a denial of service.
The patch (noted in the upstream report) fixes the flaw in magick/property.c, which exists in Fedora's versions of ImageMagick (6.6.5 and 6.7.0) and Red Hat Enterprise Linux 6 (6.5.4), however it does
http://rhn.redhat.com/errata/RHSA-2012-0544.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0545.htmlhttp://secunia.com/advisories/47926http://secunia.com/advisories/48247http://secunia.com/advisories/48259http://secunia.com/advisories/49043http://secunia.com/advisories/49063http://secunia.com/advisories/49068http://ubuntu.com/usn/usn-1435-1http://www.cert.fi/en/reports/2012/vulnerability595210.htmlhttp://www.debian.org/security/2012/dsa-2427http://www.gentoo.org/security/en/glsa/glsa-201203-09.xmlhttp://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=20286http://www.osvdb.org/79003http://www.securitytracker.com/id?1027032http://rhn.redhat.com/errata/RHSA-2012-0544.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0545.htmlhttp://secunia.com/advisories/47926http://secunia.com/advisories/48247http://secunia.com/advisories/48259http://secunia.com/advisories/49043http://secunia.com/advisories/49063http://secunia.com/advisories/49068http://ubuntu.com/usn/usn-1435-1http://www.cert.fi/en/reports/2012/vulnerability595210.htmlhttp://www.debian.org/security/2012/dsa-2427http://www.gentoo.org/security/en/glsa/glsa-201203-09.xmlhttp://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=20286http://www.osvdb.org/79003http://www.securitytracker.com/id?1027032
2012-06-05
Published