CVE-2012-0248
published 2012-06-05CVE-2012-0248: ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags…
PriorityP419medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
2.10%
79.7th percentile
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | imagemagick | < imagemagick 8:6.6.9.7-7 (bookworm) | imagemagick 8:6.6.9.7-7 (bookworm) |
| debian | imagemagick | < imagemagick 8:6.6.9.7-6 (bookworm) | imagemagick 8:6.6.9.7-6 (bookworm) |
| imagemagick | imagemagick | <= 6.7.5-8 | — |
| imagemagick | imagemagick | <= 6.7.5-7 | — |
| imagemagick | imagemagick | >= 0 < 8:6.6.9.7-6 | 8:6.6.9.7-6 |
| imagemagick | imagemagick | >= 0 < 8:6.6.9.7-7 | 8:6.6.9.7-7 |
| imagemagick | imagemagick | >= 0 < 8:6.6.9.7-6 | 8:6.6.9.7-6 |
| imagemagick | imagemagick | >= 0 < 8:6.6.9.7-7 | 8:6.6.9.7-7 |
| imagemagick | imagemagick | >= 0 < 8:6.6.9.7-6 | 8:6.6.9.7-6 |
| imagemagick | imagemagick | >= 0 < 8:6.6.9.7-7 | 8:6.6.9.7-7 |
| imagemagick | imagemagick | >= 0 < 8:6.6.9.7-6 | 8:6.6.9.7-6 |
| imagemagick | imagemagick | >= 0 < 8:6.6.9.7-7 | 8:6.6.9.7-7 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_ubuntu8.8HIGH
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2012-05-01·CVSS 8.8
CVE-2012-0247 [HIGH] ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: ImageMagick could be made to crash or run programs as your login if it
opened a specially crafted file.
Joonas Kuorilehto and Aleksis Kauppinen discovered that ImageMagick
incorrectly handled certain ResolutionUnit tags. If a user or automated
system using ImageMagick were tricked into opening a specially crafted
image, an attacker could exploit this to cause a denial of service or
possibly execute code with the privileges of the user invoking the program.
(CVE-2012-0247, CVE-2012-1185)
Joonas Kuorilehto and Aleksis Kauppinen discovered that ImageMagick
incorrectly handled certain IFD structures. If a user or automated
system using ImageMagick were tricked into opening a specially crafted
image, an attacker could exploit this to cause a denial
Red Hat
ImageMagick: Incorrect fix for CVE-2012-0248
vendor_redhat·2012-03-19·CVSS 5.5
CVE-2012-1186 [MEDIUM] ImageMagick: Incorrect fix for CVE-2012-0248
ImageMagick: Incorrect fix for CVE-2012-0248
Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted IOP tag offsets in the IFD in an image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0248.
Statement: Not vulnerable. This issue did not affect the versions of ImageMagick as shipped with Red Hat Enterprise Linux 5 and 6 as they did not backport the insufficient patch for CVE-2012-0248.
Package: ImageMagick (Red Hat Enterprise Linux 5) - Not affected
Package: ImageMagick (Red Hat Enterprise Linux 6) - Not affected
Red Hat
ImageMagick: invalid validation of images denial of service
vendor_redhat·2012-02-03·CVSS 5.5
CVE-2012-0248 [MEDIUM] ImageMagick: invalid validation of images denial of service
ImageMagick: invalid validation of images denial of service
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF.
Package: ImageMagick (Red Hat Enterprise Linux 4) - Not affected
Debian
CVE-2012-1186: imagemagick - Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6...
vendor_debian·2012·CVSS 5.5
CVE-2012-1186 [MEDIUM] CVE-2012-1186: imagemagick - Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6...
Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted IOP tag offsets in the IFD in an image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0248.
Scope: local
bookworm: resolved (fixed in 8:6.6.9.7-7)
bullseye: resolved (fixed in 8:6.6.9.7-7)
forky: resolved (fixed in 8:6.6.9.7-7)
sid: resolved (fixed in 8:6.6.9.7-7)
trixie: resolved (fixed in 8:6.6.9.7-7)
Debian
CVE-2012-0248: imagemagick - ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of ser...
vendor_debian·2012·CVSS 5.5
CVE-2012-0248 [MEDIUM] CVE-2012-0248: imagemagick - ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of ser...
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF.
Scope: local
bookworm: resolved (fixed in 8:6.6.9.7-6)
bullseye: resolved (fixed in 8:6.6.9.7-6)
forky: resolved (fixed in 8:6.6.9.7-6)
sid: resolved (fixed in 8:6.6.9.7-6)
trixie: resolved (fixed in 8:6.6.9.7-6)
GHSA
GHSA-3xpw-25qv-r984: Integer overflow in the SyncImageProfiles function in profile
ghsa_unreviewed·2022-05-13·CVSS 5.5
CVE-2012-1186 [MEDIUM] CWE-835 GHSA-3xpw-25qv-r984: Integer overflow in the SyncImageProfiles function in profile
Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted IOP tag offsets in the IFD in an image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0248.
GHSA
GHSA-jxh3-f5j5-g9vq: ImageMagick 6
ghsa_unreviewed·2022-05-04
CVE-2012-0248 [MEDIUM] CWE-835 GHSA-jxh3-f5j5-g9vq: ImageMagick 6
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF.
OSV
CVE-2012-0248: ImageMagick 6
osv·2012-06-05·CVSS 5.5
CVE-2012-0248 [MEDIUM] CVE-2012-0248: ImageMagick 6
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF.
OSV
CVE-2012-1186: Integer overflow in the SyncImageProfiles function in profile
osv·2012-06-05·CVSS 5.5
CVE-2012-1186 [MEDIUM] CVE-2012-1186: Integer overflow in the SyncImageProfiles function in profile
Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted IOP tag offsets in the IFD in an image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0248.
Suricata
ET WEB_CLIENT Internet Explorer CTableRowCellsCollectionCacheItem.GetNext Memory Use-After-Free Attempt
suricata·2012-04-04
CVE-2010-0248 ET WEB_CLIENT Internet Explorer CTableRowCellsCollectionCacheItem.GetNext Memory Use-After-Free Attempt
ET WEB_CLIENT Internet Explorer CTableRowCellsCollectionCacheItem.GetNext Memory Use-After-Free Attempt
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Internet Explorer CTableRowCellsCollectionCacheItem.GetNext Memory Use-After-Free Attempt"; flow:established,to_client; file.data; content:"document.getElementById|28 27|tableid|27 29|.cloneNode"; fast_pattern; nocase; content:"cells.urns"; nocase; distance:0; content:"cells.item"; nocase; distance:0; reference:url,dvlabs.tippingpoint.com/blog/2012/03/15/pwn2own-2012-challenge-writeup; reference:url,technet.microsoft.com/en-us/security/bulletin/MS10-002; reference:bid,37894; reference:cve,2010-0248; classtype:attempted-user; sid:2014463; rev:4; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plu
No public exploits indexed.
Bugzilla
CVE-2012-1186: ImageMagick: Incorrect fix for CVE-2012-0248
bugzilla·2012-03-19·CVSS 5.5
CVE-2012-1186 [MEDIUM] CVE-2012-1186: ImageMagick: Incorrect fix for CVE-2012-0248
CVE-2012-1186: ImageMagick: Incorrect fix for CVE-2012-0248
The original fix for CVE-2012-0248 was found to be insufficient.
The original fix for CVE-2012-0248 failed to correct the denial of service condition in "profile.c" source code part, too. This still allowed the specially-crafted image file, when processed for example by the "convert" executable, to cause original CVE-2012-0248 problem (denial of service).
Relevant upstream patch:
[1] http://trac.imagemagick.org/changeset/6998/ImageMagick/branches/ImageMagick-6.7.5/magick/profile.c
Discussion:
A CVE identifier of CVE-2012-1186 has been assigned to this issue.
---
Is upstream author informed about it?
---
(In reply to comment #2)
> Is upstream author informed about it?
Yes, they've been informed about the issues and publi
Bugzilla
CVE-2012-0247 CVE-2012-0248 ImageMagick: invalid validation of images denial of service [fedora-all]
bugzilla·2012-02-24·CVSS 8.8
CVE-2012-0247 [HIGH] CVE-2012-0247 CVE-2012-0248 ImageMagick: invalid validation of images denial of service [fedora-all]
CVE-2012-0247 CVE-2012-0248 ImageMagick: invalid validation of images denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/up
Bugzilla
CVE-2012-0247 CVE-2012-0248 ImageMagick: invalid validation of images denial of service [fedora-all]
bugzilla·2012-02-23·CVSS 8.8
CVE-2012-0247 [HIGH] CVE-2012-0247 CVE-2012-0248 ImageMagick: invalid validation of images denial of service [fedora-all]
CVE-2012-0247 CVE-2012-0248 ImageMagick: invalid validation of images denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/up
Bugzilla
CVE-2012-0247 CVE-2012-0248 ImageMagick: invalid validation of images denial of service
bugzilla·2012-02-10·CVSS 8.8
CVE-2012-0247 [HIGH] CVE-2012-0247 CVE-2012-0248 ImageMagick: invalid validation of images denial of service
CVE-2012-0247 CVE-2012-0248 ImageMagick: invalid validation of images denial of service
Two input validation and denial of service flaws were reported [1],[2] in ImageMagick:
[CVE-2012-0247] When parsing a maliciously crafted image with incorrect offset and count in the ResolutionUnit tag in EXIF IFD0, ImageMagick copies two bytes into an invalid address.
[CVE-2012-0248] When parsing a maliciously crafted image with an IFD whose all IOP tags' value offsets point to the beginning of the IFD itself. As a result, ImageMagick parses the IFD structure indefinitely, causing a denial of service.
The patch (noted in the upstream report) fixes the flaw in magick/property.c, which exists in Fedora's versions of ImageMagick (6.6.5 and 6.7.0) and Red Hat Enterprise Linux 6 (6.5.4), however it does
http://rhn.redhat.com/errata/RHSA-2012-0544.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0545.htmlhttp://secunia.com/advisories/47926http://secunia.com/advisories/48247http://secunia.com/advisories/48259http://secunia.com/advisories/49043http://secunia.com/advisories/49063http://secunia.com/advisories/49068http://ubuntu.com/usn/usn-1435-1http://www.cert.fi/en/reports/2012/vulnerability595210.htmlhttp://www.debian.org/security/2012/dsa-2427http://www.gentoo.org/security/en/glsa/glsa-201203-09.xmlhttp://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=20286http://www.osvdb.org/79003http://www.securityfocus.com/bid/51957http://www.securitytracker.com/id?1027032http://rhn.redhat.com/errata/RHSA-2012-0544.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0545.htmlhttp://secunia.com/advisories/47926http://secunia.com/advisories/48247http://secunia.com/advisories/48259http://secunia.com/advisories/49043http://secunia.com/advisories/49063http://secunia.com/advisories/49068http://ubuntu.com/usn/usn-1435-1http://www.cert.fi/en/reports/2012/vulnerability595210.htmlhttp://www.debian.org/security/2012/dsa-2427http://www.gentoo.org/security/en/glsa/glsa-201203-09.xmlhttp://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=20286http://www.osvdb.org/79003http://www.securityfocus.com/bid/51957http://www.securitytracker.com/id?1027032
2012-06-05
Published