CVE-2012-1186
published 2012-06-05CVE-2012-1186: Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a denial of service…
PriorityP419medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
1.88%
77.3th percentile
Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted IOP tag offsets in the IFD in an image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0248.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | imagemagick | < imagemagick 8:6.6.9.7-7 (bookworm) | imagemagick 8:6.6.9.7-7 (bookworm) |
| imagemagick | imagemagick | <= 6.7.5-8 | — |
| imagemagick | imagemagick | >= 0 < 8:6.6.9.7-7 | 8:6.6.9.7-7 |
| imagemagick | imagemagick | >= 0 < 8:6.6.9.7-7 | 8:6.6.9.7-7 |
| imagemagick | imagemagick | >= 0 < 8:6.6.9.7-7 | 8:6.6.9.7-7 |
| imagemagick | imagemagick | >= 0 < 8:6.6.9.7-7 | 8:6.6.9.7-7 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2012-05-01·CVSS 8.8
CVE-2012-0247 [HIGH] ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: ImageMagick could be made to crash or run programs as your login if it
opened a specially crafted file.
Joonas Kuorilehto and Aleksis Kauppinen discovered that ImageMagick
incorrectly handled certain ResolutionUnit tags. If a user or automated
system using ImageMagick were tricked into opening a specially crafted
image, an attacker could exploit this to cause a denial of service or
possibly execute code with the privileges of the user invoking the program.
(CVE-2012-0247, CVE-2012-1185)
Joonas Kuorilehto and Aleksis Kauppinen discovered that ImageMagick
incorrectly handled certain IFD structures. If a user or automated
system using ImageMagick were tricked into opening a specially crafted
image, an attacker could exploit this to cause a denial
Red Hat
ImageMagick: Incorrect fix for CVE-2012-0248
vendor_redhat·2012-03-19·CVSS 5.5
CVE-2012-1186 [MEDIUM] ImageMagick: Incorrect fix for CVE-2012-0248
ImageMagick: Incorrect fix for CVE-2012-0248
Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted IOP tag offsets in the IFD in an image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0248.
Statement: Not vulnerable. This issue did not affect the versions of ImageMagick as shipped with Red Hat Enterprise Linux 5 and 6 as they did not backport the insufficient patch for CVE-2012-0248.
Package: ImageMagick (Red Hat Enterprise Linux 5) - Not affected
Package: ImageMagick (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2012-1186: imagemagick - Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6...
vendor_debian·2012·CVSS 5.5
CVE-2012-1186 [MEDIUM] CVE-2012-1186: imagemagick - Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6...
Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted IOP tag offsets in the IFD in an image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0248.
Scope: local
bookworm: resolved (fixed in 8:6.6.9.7-7)
bullseye: resolved (fixed in 8:6.6.9.7-7)
forky: resolved (fixed in 8:6.6.9.7-7)
sid: resolved (fixed in 8:6.6.9.7-7)
trixie: resolved (fixed in 8:6.6.9.7-7)
GHSA
GHSA-3xpw-25qv-r984: Integer overflow in the SyncImageProfiles function in profile
ghsa_unreviewed·2022-05-13·CVSS 5.5
CVE-2012-1186 [MEDIUM] CWE-835 GHSA-3xpw-25qv-r984: Integer overflow in the SyncImageProfiles function in profile
Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted IOP tag offsets in the IFD in an image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0248.
OSV
CVE-2012-1186: Integer overflow in the SyncImageProfiles function in profile
osv·2012-06-05·CVSS 5.5
CVE-2012-1186 [MEDIUM] CVE-2012-1186: Integer overflow in the SyncImageProfiles function in profile
Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted IOP tag offsets in the IFD in an image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0248.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-updates/2012-06/msg00001.htmlhttp://secunia.com/advisories/47926http://secunia.com/advisories/48974http://secunia.com/advisories/49043http://secunia.com/advisories/49317http://trac.imagemagick.org/changeset/6998/ImageMagick/branches/ImageMagick-6.7.5/magick/profile.chttp://ubuntu.com/usn/usn-1435-1http://www.debian.org/security/2012/dsa-2462http://www.openwall.com/lists/oss-security/2012/03/19/5http://www.osvdb.org/80555http://www.securityfocus.com/bid/51957https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-1186https://exchange.xforce.ibmcloud.com/vulnerabilities/76139http://lists.opensuse.org/opensuse-updates/2012-06/msg00001.htmlhttp://secunia.com/advisories/47926http://secunia.com/advisories/48974http://secunia.com/advisories/49043http://secunia.com/advisories/49317http://trac.imagemagick.org/changeset/6998/ImageMagick/branches/ImageMagick-6.7.5/magick/profile.chttp://ubuntu.com/usn/usn-1435-1http://www.debian.org/security/2012/dsa-2462http://www.openwall.com/lists/oss-security/2012/03/19/5http://www.osvdb.org/80555http://www.securityfocus.com/bid/51957https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-1186https://exchange.xforce.ibmcloud.com/vulnerabilities/76139
2012-06-05
Published