CVE-2012-1798Out-of-bounds Read in Imagemagick

CWE-125Out-of-bounds Read9 documents8 sources
Severity
6.5MEDIUMNVD
EPSS
1.4%
top 19.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 5
Latest updateMay 13

Description

The TIFFGetEXIFProperties function in coders/tiff.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted EXIF IFD in a TIFF image.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages7 packages

Debianimagemagick/imagemagick< 8:6.7.4.0-4+3
NVDopensuse/opensuse11.4, 12.1+1

Also affects: Debian Linux 6.0, Enterprise Linux 6.2

Patches

🔴Vulnerability Details

3
GHSA
GHSA-xj4q-67vj-g953: The TIFFGetEXIFProperties function in coders/tiff2022-05-13
CVEList
CVE-2012-1798: The TIFFGetEXIFProperties function in coders/tiff2012-06-05
OSV
CVE-2012-1798: The TIFFGetEXIFProperties function in coders/tiff2012-06-05

📋Vendor Advisories

3
Ubuntu
ImageMagick vulnerabilities2012-05-01
Red Hat
ImageMagick: Out-of-bounds buffer read by copying image bytes for TIFF images with crafted TIFF EXIF IFD value2012-03-28
Debian
CVE-2012-1798: imagemagick - The TIFFGetEXIFProperties function in coders/tiff.c in ImageMagick before 6.7.6-...2012

💬Community

2
Bugzilla
CVE-2012-1798 ImageMagick: Out-of-bounds buffer read by copying image bytes for TIFF images with crafted TIFF EXIF IFD value2012-03-29
Bugzilla
CVE-2012-0259 CVE-2012-0260 CVE-2012-1798 ImageMagick various flaws [fedora-all]2012-03-29
CVE-2012-1798 — Out-of-bounds Read in Imagemagick | cvebase