CVE-2021-3610
published 2022-02-24CVE-2021-3610: A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an…
high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imagemagick | < imagemagick 8:6.9.11.60+dfsg-1.6+deb12u1 (bookworm) | imagemagick 8:6.9.11.60+dfsg-1.6+deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.3+deb11u3 | 8:6.9.11.60+dfsg-1.3+deb11u3 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.6+deb12u1 | 8:6.9.11.60+dfsg-1.6+deb12u1 |
| imagemagick | imagemagick | >= 0 < 8:6.9.12.98+dfsg1-2 | 8:6.9.12.98+dfsg1-2 |
| imagemagick | imagemagick | >= 0 < 8:6.9.12.98+dfsg1-2 | 8:6.9.12.98+dfsg1-2 |
| imagemagick | imagemagick | >= 0 < 8:6.9.10.23+dfsg-2.1ubuntu11.9 | 8:6.9.10.23+dfsg-2.1ubuntu11.9 |
| imagemagick | imagemagick | >= 0 < 8:6.9.10.23+dfsg-2.1ubuntu11.10 | 8:6.9.10.23+dfsg-2.1ubuntu11.10 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5 | 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5 |
| imagemagick | imagemagick | >= 0 < 8:6.8.9.9-7ubuntu5.16+esm8 | 8:6.8.9.9-7ubuntu5.16+esm8 |
| imagemagick | imagemagick | >= 0 < 8:6.9.7.4+dfsg-16ubuntu6.15+esm1 | 8:6.9.7.4+dfsg-16ubuntu6.15+esm1 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+esm2 | 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+esm2 |
| imagemagick | imagemagick | >= 6.9.10.88 < 6.9.12-14 | 6.9.12-14 |
| imagemagick | imagemagick | >= 7.0.0-0 < 7.0.11-14 | 7.0.11-14 |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2024-07-25·CVSS 7.8
CVE-2023-1289 [HIGH] ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: Several security issues were fixed in ImageMagick.
USN-6200-1 fixed vulnerabilities in ImageMagick. Unfortunately these fixes were
incomplete for Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. This update fixes the
problem.
Original advisory details:
It was discovered that ImageMagick incorrectly handled the "-authenticate"
option for password-protected PDF files. An attacker could possibly use
this issue to inject additional shell commands and perform arbitrary code
execution. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-29599)
It was discovered that ImageMagick incorrectly handled certain values
when processing PDF files. If a user or automated system using ImageMagick
were tricked into opening a specially crafted PDF file, an attacker co
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2023-07-04·CVSS 7.8
CVE-2023-1289 [HIGH] ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: Several security issues were fixed in ImageMagick.
It was discovered that ImageMagick incorrectly handled the "-authenticate"
option for password-protected PDF files. An attacker could possibly use
this issue to inject additional shell commands and perform arbitrary code
execution. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-29599)
It was discovered that ImageMagick incorrectly handled certain values
when processing PDF files. If a user or automated system using ImageMagick
were tricked into opening a specially crafted PDF file, an attacker could
exploit this to cause a denial of service. This issue only affected Ubuntu
20.04 LTS. (CVE-2021-20224)
Zhang Xiaohui discovered that ImageMagick incorrectly handled certain
values when proce
Red Hat
ImageMagick: heap-based buffer overflow in ReadTIFFImage() in coders/tiff.c
vendor_redhat·2021-05-27·CVSS 7.5
CVE-2021-3610 [HIGH] CWE-787 ImageMagick: heap-based buffer overflow in ReadTIFFImage() in coders/tiff.c
ImageMagick: heap-based buffer overflow in ReadTIFFImage() in coders/tiff.c
A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault.
A heap-based buffer overflow vulnerability was found in ImageMagick in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault.
Statement: All versions of ImageMagick shipped in Red Hat Enterprise Linux 5, 6, and 7 are not affected by this flaw as they do not contain vulnerable code. The vulnerable code was introduced in a subsequent version of ImageMagick.
Package: Imag
Debian
CVE-2021-3610: imagemagick - A heap-based buffer overflow vulnerability was found in ImageMagick in versions ...
vendor_debian·2021·CVSS 7.5
CVE-2021-3610 [HIGH] CVE-2021-3610: imagemagick - A heap-based buffer overflow vulnerability was found in ImageMagick in versions ...
A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.60+dfsg-1.6+deb12u1)
bullseye: resolved (fixed in 8:6.9.11.60+dfsg-1.3+deb11u3)
forky: resolved (fixed in 8:6.9.12.98+dfsg1-2)
sid: resolved (fixed in 8:6.9.12.98+dfsg1-2)
trixie: resolved (fixed in 8:6.9.12.98+dfsg1-2)
OSV
imagemagick vulnerabilities
osv·2024-07-25·CVSS 7.8
[HIGH] imagemagick vulnerabilities
imagemagick vulnerabilities
USN-6200-1 fixed vulnerabilities in ImageMagick. Unfortunately these fixes were
incomplete for Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. This update fixes the
problem.
Original advisory details:
It was discovered that ImageMagick incorrectly handled the "-authenticate"
option for password-protected PDF files. An attacker could possibly use
this issue to inject additional shell commands and perform arbitrary code
execution. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-29599)
It was discovered that ImageMagick incorrectly handled certain values
when processing PDF files. If a user or automated system using ImageMagick
were tricked into opening a specially crafted PDF file, an attacker could
exploit this to cause a denial of service. This issue only affec
OSV
imagemagick vulnerabilities
osv·2023-07-04·CVSS 7.8
CVE-2020-29599 [HIGH] imagemagick vulnerabilities
imagemagick vulnerabilities
It was discovered that ImageMagick incorrectly handled the "-authenticate"
option for password-protected PDF files. An attacker could possibly use
this issue to inject additional shell commands and perform arbitrary code
execution. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-29599)
It was discovered that ImageMagick incorrectly handled certain values
when processing PDF files. If a user or automated system using ImageMagick
were tricked into opening a specially crafted PDF file, an attacker could
exploit this to cause a denial of service. This issue only affected Ubuntu
20.04 LTS. (CVE-2021-20224)
Zhang Xiaohui discovered that ImageMagick incorrectly handled certain
values when processing image data. If a user or automated system using
ImageMagick we
GHSA
GHSA-x4cj-7x5p-w7vf: A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7
ghsa_unreviewed·2022-02-25
CVE-2021-3610 [HIGH] CWE-125 GHSA-x4cj-7x5p-w7vf: A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7
A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault.
OSV
CVE-2021-3610: A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7
osv·2022-02-24·CVSS 7.5
CVE-2021-3610 [HIGH] CVE-2021-3610: A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7
A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2023/05/29/4http://www.openwall.com/lists/oss-security/2023/06/05/1https://bugzilla.redhat.com/show_bug.cgi?id=1973689https://github.com/ImageMagick/ImageMagick/commit/930ff0d1a9bc42925a7856e9ea53f5fc9f318bf3http://www.openwall.com/lists/oss-security/2023/05/29/4http://www.openwall.com/lists/oss-security/2023/06/05/1https://bugzilla.redhat.com/show_bug.cgi?id=1973689https://github.com/ImageMagick/ImageMagick/commit/930ff0d1a9bc42925a7856e9ea53f5fc9f318bf3https://github.com/fuzzing2026/CVE-PoCs/tree/main/imagemagick-CVE-2021-3610
2022-02-24
Published