CVE-2021-3596
published 2022-02-24CVE-2021-3596: A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not checking…
medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not checking the return value from libxml2's xmlCreatePushParserCtxt() and uses the value directly, which leads to a crash and segmentation fault.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | imagemagick | < imagemagick 8:6.9.11.57+dfsg-1 (bookworm) | imagemagick 8:6.9.11.57+dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| imagemagick | imagemagick | < 7.0.10-31 | 7.0.10-31 |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.57+dfsg-1 | 8:6.9.11.57+dfsg-1 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.57+dfsg-1 | 8:6.9.11.57+dfsg-1 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.57+dfsg-1 | 8:6.9.11.57+dfsg-1 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.57+dfsg-1 | 8:6.9.11.57+dfsg-1 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM
GHSA
GHSA-8jv5-qv7g-fm4r: A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7
ghsa_unreviewed·2022-02-25
CVE-2021-3596 [MEDIUM] CWE-476 GHSA-8jv5-qv7g-fm4r: A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7
A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not checking the return value from libxml2's xmlCreatePushParserCtxt() and uses the value directly, which leads to a crash and segmentation fault.
OSV
CVE-2021-3596: A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7
osv·2022-02-24·CVSS 6.5
CVE-2021-3596 [MEDIUM] CVE-2021-3596: A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7
A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not checking the return value from libxml2's xmlCreatePushParserCtxt() and uses the value directly, which leads to a crash and segmentation fault.
Debian
CVE-2021-3596: imagemagick - A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7....
vendor_debian·2021·CVSS 6.5
CVE-2021-3596 [MEDIUM] CVE-2021-3596: imagemagick - A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7....
A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not checking the return value from libxml2's xmlCreatePushParserCtxt() and uses the value directly, which leads to a crash and segmentation fault.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.57+dfsg-1)
bullseye: resolved (fixed in 8:6.9.11.57+dfsg-1)
forky: resolved (fixed in 8:6.9.11.57+dfsg-1)
sid: resolved (fixed in 8:6.9.11.57+dfsg-1)
trixie: resolved (fixed in 8:6.9.11.57+dfsg-1)
Red Hat
ImageMagick: NULL pointer dereference in ReadSVGImage() in coders/svg.c
vendor_redhat·2020-09-25·CVSS 6.5
CVE-2021-3596 [MEDIUM] CWE-476 ImageMagick: NULL pointer dereference in ReadSVGImage() in coders/svg.c
ImageMagick: NULL pointer dereference in ReadSVGImage() in coders/svg.c
A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not checking the return value from libxml2's xmlCreatePushParserCtxt() and uses the value directly, which leads to a crash and segmentation fault.
A NULL pointer dereference flaw was found in ImageMagick in ReadSVGImage() in coders/svg.c . This issue is due to not checking the return value from libxml2's xmlCreatePushParserCtxt() and uses the value directly, which leads to a crash and segmentation fault.
Package: ImageMagick (Red Hat Enterprise Linux 5) - Out of support scope
Package: ImageMagick (Red Hat Enterprise Linux 6) - Out of support scope
Package: ImageMagick (Red
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1970569https://github.com/ImageMagick/ImageMagick/issues/2624https://lists.debian.org/debian-lts-announce/2022/05/msg00018.htmlhttps://lists.debian.org/debian-lts-announce/2023/03/msg00008.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1970569https://github.com/ImageMagick/ImageMagick/issues/2624https://lists.debian.org/debian-lts-announce/2022/05/msg00018.htmlhttps://lists.debian.org/debian-lts-announce/2023/03/msg00008.html
2022-02-24
Published