CVE-2012-0259 — Out-of-bounds Read in Imagemagick
Severity
7.5HIGHNVD
NVD6.5OSV6.5
EPSS
1.4%
top 19.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 5
Latest updateMay 13
Description
The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (crash) via a zero value in the component count of an EXIF XResolution tag in a JPEG file, which triggers an out-of-bounds read.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6
Affected Packages4 packages
Also affects: Debian Linux 6.0, Ubuntu Linux 10.04, 11.04, 11.10, 12.04
Patches
🔴Vulnerability Details
4GHSA
▶
📋Vendor Advisories
5Red Hat▶
ImageMagick: integer overflow in the GetEXIFProperty function in magick/property.c could lead to DoS↗2020-07-31
Red Hat▶
ImageMagick: Out-of heap-based buffer read by processing crafted JPEG EXIF header tag value↗2012-03-28
Debian▶
CVE-2012-1610: imagemagick - Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMa...↗2012
Debian▶
CVE-2012-0259: imagemagick - The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 ...↗2012