CVE-2012-0259
published 2012-06-05CVE-2012-0259: The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (crash) via a zero value…
PriorityP423medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
2.36%
81.8th percentile
The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (crash) via a zero value in the component count of an EXIF XResolution tag in a JPEG file, which triggers an out-of-bounds read.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | imagemagick | < imagemagick 8:6.7.4.0-4 (bookworm) | imagemagick 8:6.7.4.0-4 (bookworm) |
| imagemagick | imagemagick | < 6.7.6-3 | 6.7.6-3 |
| imagemagick | imagemagick | < 6.7.6-4 | 6.7.6-4 |
| imagemagick | imagemagick | >= 0 < 8:6.7.4.0-4 | 8:6.7.4.0-4 |
| imagemagick | imagemagick | >= 0 < 8:6.7.4.0-4 | 8:6.7.4.0-4 |
| imagemagick | imagemagick | >= 0 < 8:6.7.4.0-4 | 8:6.7.4.0-4 |
| imagemagick | imagemagick | >= 0 < 8:6.7.4.0-4 | 8:6.7.4.0-4 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_ubuntu8.8HIGH
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ImageMagick: integer overflow in the GetEXIFProperty function in magick/property.c could lead to DoS
vendor_redhat·2020-07-31·CVSS 6.5
CVE-2012-1610 [MEDIUM] CWE-190 ImageMagick: integer overflow in the GetEXIFProperty function in magick/property.c could lead to DoS
ImageMagick: integer overflow in the GetEXIFProperty function in magick/property.c could lead to DoS
Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-4 allows remote attackers to cause a denial of service (out-of-bounds read) via a large component count for certain EXIF tags in a JPEG image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0259.
Statement: ImageMagick as shipped with Red Hat Enterprise Linux 7 and 8 is not affected by this flaw, as the versions shipped have already been patched.
Package: ImageMagick (Red Hat Enterprise Linux 5) - Out of support scope
Package: ImageMagick (Red Hat Enterprise Linux 6) - Out of support scope
Package: ImageMagick (Red Hat Enterprise Linux 7) - Not affected
Package:
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2012-05-01·CVSS 8.8
CVE-2012-0247 [HIGH] ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: ImageMagick could be made to crash or run programs as your login if it
opened a specially crafted file.
Joonas Kuorilehto and Aleksis Kauppinen discovered that ImageMagick
incorrectly handled certain ResolutionUnit tags. If a user or automated
system using ImageMagick were tricked into opening a specially crafted
image, an attacker could exploit this to cause a denial of service or
possibly execute code with the privileges of the user invoking the program.
(CVE-2012-0247, CVE-2012-1185)
Joonas Kuorilehto and Aleksis Kauppinen discovered that ImageMagick
incorrectly handled certain IFD structures. If a user or automated
system using ImageMagick were tricked into opening a specially crafted
image, an attacker could exploit this to cause a denial
Red Hat
ImageMagick: Out-of heap-based buffer read by processing crafted JPEG EXIF header tag value
vendor_redhat·2012-03-28·CVSS 6.5
CVE-2012-0259 [MEDIUM] ImageMagick: Out-of heap-based buffer read by processing crafted JPEG EXIF header tag value
ImageMagick: Out-of heap-based buffer read by processing crafted JPEG EXIF header tag value
The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (crash) via a zero value in the component count of an EXIF XResolution tag in a JPEG file, which triggers an out-of-bounds read.
Statement: Not vulnerable. This issue did not affect the versions of ImageMagick as shipped with Red Hat Enterprise Linux 6 as it did not backport the insufficient patch for CVE-2012-0259.
Package: ImageMagick (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2012-1610: imagemagick - Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMa...
vendor_debian·2012·CVSS 6.5
CVE-2012-1610 [MEDIUM] CVE-2012-1610: imagemagick - Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMa...
Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-4 allows remote attackers to cause a denial of service (out-of-bounds read) via a large component count for certain EXIF tags in a JPEG image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0259.
Scope: local
bookworm: resolved (fixed in 8:6.7.4.0-4)
bullseye: resolved (fixed in 8:6.7.4.0-4)
forky: resolved (fixed in 8:6.7.4.0-4)
sid: resolved (fixed in 8:6.7.4.0-4)
trixie: resolved (fixed in 8:6.7.4.0-4)
Debian
CVE-2012-0259: imagemagick - The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 ...
vendor_debian·2012·CVSS 6.5
CVE-2012-0259 [MEDIUM] CVE-2012-0259: imagemagick - The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 ...
The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (crash) via a zero value in the component count of an EXIF XResolution tag in a JPEG file, which triggers an out-of-bounds read.
Scope: local
bookworm: resolved (fixed in 8:6.7.4.0-4)
bullseye: resolved (fixed in 8:6.7.4.0-4)
forky: resolved (fixed in 8:6.7.4.0-4)
sid: resolved (fixed in 8:6.7.4.0-4)
trixie: resolved (fixed in 8:6.7.4.0-4)
GHSA
GHSA-6gr8-x4xf-h967: Integer overflow in the GetEXIFProperty function in magick/property
ghsa_unreviewed·2022-05-13·CVSS 6.5
CVE-2012-1610 [MEDIUM] CWE-190 GHSA-6gr8-x4xf-h967: Integer overflow in the GetEXIFProperty function in magick/property
Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-4 allows remote attackers to cause a denial of service (out-of-bounds read) via a large component count for certain EXIF tags in a JPEG image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0259.
GHSA
GHSA-fq4j-xxf4-7frh: The GetEXIFProperty function in magick/property
ghsa_unreviewed·2022-05-04
CVE-2012-0259 [MEDIUM] CWE-125 GHSA-fq4j-xxf4-7frh: The GetEXIFProperty function in magick/property
The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (crash) via a zero value in the component count of an EXIF XResolution tag in a JPEG file, which triggers an out-of-bounds read.
OSV
CVE-2012-0259: The GetEXIFProperty function in magick/property
osv·2012-06-05·CVSS 6.5
CVE-2012-0259 [MEDIUM] CVE-2012-0259: The GetEXIFProperty function in magick/property
The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (crash) via a zero value in the component count of an EXIF XResolution tag in a JPEG file, which triggers an out-of-bounds read.
OSV
CVE-2012-1610: Integer overflow in the GetEXIFProperty function in magick/property
osv·2012-06-05·CVSS 6.5
CVE-2012-1610 [MEDIUM] CVE-2012-1610: Integer overflow in the GetEXIFProperty function in magick/property
Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-4 allows remote attackers to cause a denial of service (out-of-bounds read) via a large component count for certain EXIF tags in a JPEG image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0259.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-0259 ImageMagick: Out-of heap-based buffer read by processing crafted JPEG EXIF header tag value
bugzilla·2012-03-29·CVSS 6.5
CVE-2012-0259 [MEDIUM] CVE-2012-0259 ImageMagick: Out-of heap-based buffer read by processing crafted JPEG EXIF header tag value
CVE-2012-0259 ImageMagick: Out-of heap-based buffer read by processing crafted JPEG EXIF header tag value
An out-of heap-based buffer read flaw was found in the way ImageMagick, an image display and manipulation tool for the X Window System, retrieved Exchangeable image file format (Exif) header tag information from certain JPEG files. A remote attacker could provide a JPEG image file, with EXIF header containing specially-crafted tag values, which once opened in some ImageMagick tool would lead to the crash of that tool (denial of service).
Upstream patch:
[1] http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=20629
Discussion:
Acknowledgements:
Red Hat would like to thank CERT-FI for reporting this issue. CERT-FI acknowledges Aleksis Kauppinen, Joonas Kuorilehto, Tuomas
Bugzilla
CVE-2012-0259 CVE-2012-0260 CVE-2012-1798 ImageMagick various flaws [fedora-all]
bugzilla·2012-03-29·CVSS 6.5
CVE-2012-0259 [MEDIUM] CVE-2012-0259 CVE-2012-0260 CVE-2012-1798 ImageMagick various flaws [fedora-all]
CVE-2012-0259 CVE-2012-0260 CVE-2012-1798 ImageMagick various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=sec
http://lists.opensuse.org/opensuse-updates/2012-06/msg00001.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0544.htmlhttp://secunia.com/advisories/48679http://secunia.com/advisories/48974http://secunia.com/advisories/49043http://secunia.com/advisories/49063http://secunia.com/advisories/49317http://secunia.com/advisories/55035http://ubuntu.com/usn/usn-1435-1http://www.cert.fi/en/reports/2012/vulnerability635606.htmlhttp://www.debian.org/security/2012/dsa-2462http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=20629http://www.osvdb.org/81021http://www.securityfocus.com/bid/52898http://www.securitytracker.com/id?1027032https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-0259https://exchange.xforce.ibmcloud.com/vulnerabilities/74657http://lists.opensuse.org/opensuse-updates/2012-06/msg00001.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0544.htmlhttp://secunia.com/advisories/48679http://secunia.com/advisories/48974http://secunia.com/advisories/49043http://secunia.com/advisories/49063http://secunia.com/advisories/49317http://secunia.com/advisories/55035http://ubuntu.com/usn/usn-1435-1http://www.cert.fi/en/reports/2012/vulnerability635606.htmlhttp://www.debian.org/security/2012/dsa-2462http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=20629http://www.osvdb.org/81021http://www.securityfocus.com/bid/52898http://www.securitytracker.com/id?1027032https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-0259https://exchange.xforce.ibmcloud.com/vulnerabilities/74657
2012-06-05
Published