CVE-2012-0260
published 2012-06-05CVE-2012-0260: The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (memory consumption) via a…
PriorityP426medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
2.36%
82.0th percentile
The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (memory consumption) via a JPEG image with a crafted sequence of restart markers.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | imagemagick | < imagemagick 8:6.7.4.0-4 (bookworm) | imagemagick 8:6.7.4.0-4 (bookworm) |
| imagemagick | imagemagick | < 6.7.6-3 | 6.7.6-3 |
| imagemagick | imagemagick | >= 0 < 8:6.7.4.0-4 | 8:6.7.4.0-4 |
| imagemagick | imagemagick | >= 0 < 8:6.7.4.0-4 | 8:6.7.4.0-4 |
| imagemagick | imagemagick | >= 0 < 8:6.7.4.0-4 | 8:6.7.4.0-4 |
| imagemagick | imagemagick | >= 0 < 8:6.7.4.0-4 | 8:6.7.4.0-4 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_aus | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | storage | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2014-03-06·CVSS 6.5
CVE-2012-0260 [MEDIUM] ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: ImageMagick could be made to crash or run programs if it opened a specially
crafted image file.
Aleksis Kauppinen, Joonas Kuorilehto and Tuomas Parttimaa discovered that
ImageMagick incorrectly handled certain restart markers in JPEG images. If
a user or automated system using ImageMagick were tricked into opening a
specially crafted JPEG image, an attacker could exploit this to cause
memory consumption, resulting in a denial of service. This issue only
affected Ubuntu 12.04 LTS. (CVE-2012-0260)
It was discovered that ImageMagick incorrectly handled decoding certain PSD
images. If a user or automated system using ImageMagick were tricked into
opening a specially crafted PSD image, an attacker could exploit this to
cause a denial of service or
Red Hat
ImageMagick: excessive CPU use DoS by processing JPEG images with crafted restart markers
vendor_redhat·2012-03-28·CVSS 6.5
CVE-2012-0260 [MEDIUM] ImageMagick: excessive CPU use DoS by processing JPEG images with crafted restart markers
ImageMagick: excessive CPU use DoS by processing JPEG images with crafted restart markers
The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (memory consumption) via a JPEG image with a crafted sequence of restart markers.
Debian
CVE-2012-0260: imagemagick - The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 a...
vendor_debian·2012·CVSS 6.5
CVE-2012-0260 [MEDIUM] CVE-2012-0260: imagemagick - The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 a...
The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (memory consumption) via a JPEG image with a crafted sequence of restart markers.
Scope: local
bookworm: resolved (fixed in 8:6.7.4.0-4)
bullseye: resolved (fixed in 8:6.7.4.0-4)
forky: resolved (fixed in 8:6.7.4.0-4)
sid: resolved (fixed in 8:6.7.4.0-4)
trixie: resolved (fixed in 8:6.7.4.0-4)
GHSA
GHSA-xqm6-6gwm-hwpw: The JPEGWarningHandler function in coders/jpeg
ghsa_unreviewed·2022-05-04
CVE-2012-0260 [MEDIUM] CWE-400 GHSA-xqm6-6gwm-hwpw: The JPEGWarningHandler function in coders/jpeg
The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (memory consumption) via a JPEG image with a crafted sequence of restart markers.
OSV
CVE-2012-0260: The JPEGWarningHandler function in coders/jpeg
osv·2012-06-05·CVSS 6.5
CVE-2012-0260 [MEDIUM] CVE-2012-0260: The JPEGWarningHandler function in coders/jpeg
The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (memory consumption) via a JPEG image with a crafted sequence of restart markers.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-0260 ImageMagick: excessive CPU use DoS by processing JPEG images with crafted restart markers
bugzilla·2012-03-29·CVSS 6.5
CVE-2012-0260 [MEDIUM] CVE-2012-0260 ImageMagick: excessive CPU use DoS by processing JPEG images with crafted restart markers
CVE-2012-0260 ImageMagick: excessive CPU use DoS by processing JPEG images with crafted restart markers
A denial of service flaw was found in the way ImageMagick, an image display and manipulation tool for the X Window System, decoded certain JPEG images. A remote attacker could provide a JPEG image with specially-crafted values / sequences of RST0 up to RST7 restart markers (used to indicate the input stream to be corrupted), which once processed by some ImageMagick tool would lead that tool to consume excessive amount of CPU time (denial of service).
Upstream patch:
[1] http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=20629
Discussion:
Acknowledgements:
Red Hat would like to thank CERT-FI for reporting this issue. CERT-FI acknowledges Aleksis Kauppinen, Joonas Kuoril
Bugzilla
CVE-2012-0259 CVE-2012-0260 CVE-2012-1798 ImageMagick various flaws [fedora-all]
bugzilla·2012-03-29·CVSS 6.5
CVE-2012-0259 [MEDIUM] CVE-2012-0259 CVE-2012-0260 CVE-2012-1798 ImageMagick various flaws [fedora-all]
CVE-2012-0259 CVE-2012-0260 CVE-2012-1798 ImageMagick various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=sec
http://lists.opensuse.org/opensuse-updates/2012-06/msg00001.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0544.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0545.htmlhttp://secunia.com/advisories/48974http://secunia.com/advisories/49063http://secunia.com/advisories/49068http://secunia.com/advisories/49317http://secunia.com/advisories/55035http://secunia.com/advisories/57224http://www.cert.fi/en/reports/2012/vulnerability635606.htmlhttp://www.debian.org/security/2012/dsa-2462http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=20629http://www.osvdb.org/81022http://www.securityfocus.com/bid/52898http://www.securitytracker.com/id?1027032http://www.ubuntu.com/usn/USN-2132-1https://exchange.xforce.ibmcloud.com/vulnerabilities/74658http://lists.opensuse.org/opensuse-updates/2012-06/msg00001.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0544.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0545.htmlhttp://secunia.com/advisories/48974http://secunia.com/advisories/49063http://secunia.com/advisories/49068http://secunia.com/advisories/49317http://secunia.com/advisories/55035http://secunia.com/advisories/57224http://www.cert.fi/en/reports/2012/vulnerability635606.htmlhttp://www.debian.org/security/2012/dsa-2462http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=20629http://www.osvdb.org/81022http://www.securityfocus.com/bid/52898http://www.securitytracker.com/id?1027032http://www.ubuntu.com/usn/USN-2132-1https://exchange.xforce.ibmcloud.com/vulnerabilities/74658
2012-06-05
Published