CVE-2012-1610
published 2012-06-05CVE-2012-1610: Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-4 allows remote attackers to cause a denial of service…
PriorityP334high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
4.75%
90.9th percentile
Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-4 allows remote attackers to cause a denial of service (out-of-bounds read) via a large component count for certain EXIF tags in a JPEG image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0259.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | imagemagick | < imagemagick 8:6.7.4.0-4 (bookworm) | imagemagick 8:6.7.4.0-4 (bookworm) |
| imagemagick | imagemagick | < 6.7.6-4 | 6.7.6-4 |
| imagemagick | imagemagick | >= 0 < 8:6.7.4.0-4 | 8:6.7.4.0-4 |
| imagemagick | imagemagick | >= 0 < 8:6.7.4.0-4 | 8:6.7.4.0-4 |
| imagemagick | imagemagick | >= 0 < 8:6.7.4.0-4 | 8:6.7.4.0-4 |
| imagemagick | imagemagick | >= 0 < 8:6.7.4.0-4 | 8:6.7.4.0-4 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_ubuntu8.8HIGH
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ImageMagick: integer overflow in the GetEXIFProperty function in magick/property.c could lead to DoS
vendor_redhat·2020-07-31·CVSS 6.5
CVE-2012-1610 [MEDIUM] CWE-190 ImageMagick: integer overflow in the GetEXIFProperty function in magick/property.c could lead to DoS
ImageMagick: integer overflow in the GetEXIFProperty function in magick/property.c could lead to DoS
Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-4 allows remote attackers to cause a denial of service (out-of-bounds read) via a large component count for certain EXIF tags in a JPEG image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0259.
Statement: ImageMagick as shipped with Red Hat Enterprise Linux 7 and 8 is not affected by this flaw, as the versions shipped have already been patched.
Package: ImageMagick (Red Hat Enterprise Linux 5) - Out of support scope
Package: ImageMagick (Red Hat Enterprise Linux 6) - Out of support scope
Package: ImageMagick (Red Hat Enterprise Linux 7) - Not affected
Package:
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2012-05-01·CVSS 8.8
CVE-2012-0247 [HIGH] ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: ImageMagick could be made to crash or run programs as your login if it
opened a specially crafted file.
Joonas Kuorilehto and Aleksis Kauppinen discovered that ImageMagick
incorrectly handled certain ResolutionUnit tags. If a user or automated
system using ImageMagick were tricked into opening a specially crafted
image, an attacker could exploit this to cause a denial of service or
possibly execute code with the privileges of the user invoking the program.
(CVE-2012-0247, CVE-2012-1185)
Joonas Kuorilehto and Aleksis Kauppinen discovered that ImageMagick
incorrectly handled certain IFD structures. If a user or automated
system using ImageMagick were tricked into opening a specially crafted
image, an attacker could exploit this to cause a denial
Debian
CVE-2012-1610: imagemagick - Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMa...
vendor_debian·2012·CVSS 6.5
CVE-2012-1610 [MEDIUM] CVE-2012-1610: imagemagick - Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMa...
Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-4 allows remote attackers to cause a denial of service (out-of-bounds read) via a large component count for certain EXIF tags in a JPEG image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0259.
Scope: local
bookworm: resolved (fixed in 8:6.7.4.0-4)
bullseye: resolved (fixed in 8:6.7.4.0-4)
forky: resolved (fixed in 8:6.7.4.0-4)
sid: resolved (fixed in 8:6.7.4.0-4)
trixie: resolved (fixed in 8:6.7.4.0-4)
GHSA
GHSA-6gr8-x4xf-h967: Integer overflow in the GetEXIFProperty function in magick/property
ghsa_unreviewed·2022-05-13·CVSS 6.5
CVE-2012-1610 [MEDIUM] CWE-190 GHSA-6gr8-x4xf-h967: Integer overflow in the GetEXIFProperty function in magick/property
Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-4 allows remote attackers to cause a denial of service (out-of-bounds read) via a large component count for certain EXIF tags in a JPEG image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0259.
OSV
CVE-2012-1610: Integer overflow in the GetEXIFProperty function in magick/property
osv·2012-06-05·CVSS 6.5
CVE-2012-1610 [MEDIUM] CVE-2012-1610: Integer overflow in the GetEXIFProperty function in magick/property
Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-4 allows remote attackers to cause a denial of service (out-of-bounds read) via a large component count for certain EXIF tags in a JPEG image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0259.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-1610 ImageMagick: integer overflow in the GetEXIFProperty function in magick/property.c could lead to DoS
bugzilla·2020-08-12·CVSS 7.5
CVE-2012-1610 [HIGH] CVE-2012-1610 ImageMagick: integer overflow in the GetEXIFProperty function in magick/property.c could lead to DoS
CVE-2012-1610 ImageMagick: integer overflow in the GetEXIFProperty function in magick/property.c could lead to DoS
Integer overflow in the GetEXIFProperty function in magick/property.c allows remote attackers to cause a DoS via a large component count for certain EXIF tags in a JPEG image.
Upstream Reference:
http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=20629
Discussion:
This flaw is out of support scope for the following products:
* Red Hat Enterprise Linux 5
* Red Hat Enterprise Linux 6
See [1] for more detailed information on support scopes.
ImageMagick as shipped with Red Hat Enterprise Linux 7 and 8 is not affected by this flaw, as the versions shipped have already been patched.
1. https://access.redhat.com/support/policy/updates/errata/
---
Statement:
I
Bugzilla
CVE-2012-0259 ImageMagick: Out-of heap-based buffer read by processing crafted JPEG EXIF header tag value
bugzilla·2012-03-29·CVSS 6.5
CVE-2012-0259 [MEDIUM] CVE-2012-0259 ImageMagick: Out-of heap-based buffer read by processing crafted JPEG EXIF header tag value
CVE-2012-0259 ImageMagick: Out-of heap-based buffer read by processing crafted JPEG EXIF header tag value
An out-of heap-based buffer read flaw was found in the way ImageMagick, an image display and manipulation tool for the X Window System, retrieved Exchangeable image file format (Exif) header tag information from certain JPEG files. A remote attacker could provide a JPEG image file, with EXIF header containing specially-crafted tag values, which once opened in some ImageMagick tool would lead to the crash of that tool (denial of service).
Upstream patch:
[1] http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=20629
Discussion:
Acknowledgements:
Red Hat would like to thank CERT-FI for reporting this issue. CERT-FI acknowledges Aleksis Kauppinen, Joonas Kuorilehto, Tuomas
http://lists.opensuse.org/opensuse-updates/2012-06/msg00001.htmlhttp://secunia.com/advisories/48974http://secunia.com/advisories/49043http://secunia.com/advisories/49317http://secunia.com/advisories/55035http://ubuntu.com/usn/usn-1435-1http://www.debian.org/security/2012/dsa-2462http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=20629http://www.openwall.com/lists/oss-security/2012/04/04/6http://www.osvdb.org/81024http://www.securityfocus.com/bid/52898https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-0259https://exchange.xforce.ibmcloud.com/vulnerabilities/74660http://lists.opensuse.org/opensuse-updates/2012-06/msg00001.htmlhttp://secunia.com/advisories/48974http://secunia.com/advisories/49043http://secunia.com/advisories/49317http://secunia.com/advisories/55035http://ubuntu.com/usn/usn-1435-1http://www.debian.org/security/2012/dsa-2462http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=20629http://www.openwall.com/lists/oss-security/2012/04/04/6http://www.osvdb.org/81024http://www.securityfocus.com/bid/52898https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-0259https://exchange.xforce.ibmcloud.com/vulnerabilities/74660
2012-06-05
Published