cbcvebase.
CVE-2021-3610
published 2022-02-24

CVE-2021-3610: A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianimagemagick< imagemagick 8:6.9.11.60+dfsg-1.6+deb12u1 (bookworm)imagemagick 8:6.9.11.60+dfsg-1.6+deb12u1 (bookworm)
fedoraprojectfedora
imagemagickimagemagick
imagemagickimagemagick>= 0 < 8:6.9.11.60+dfsg-1.3+deb11u38:6.9.11.60+dfsg-1.3+deb11u3
imagemagickimagemagick>= 0 < 8:6.9.11.60+dfsg-1.6+deb12u18:6.9.11.60+dfsg-1.6+deb12u1
imagemagickimagemagick>= 0 < 8:6.9.12.98+dfsg1-28:6.9.12.98+dfsg1-2
imagemagickimagemagick>= 0 < 8:6.9.12.98+dfsg1-28:6.9.12.98+dfsg1-2
imagemagickimagemagick>= 0 < 8:6.9.10.23+dfsg-2.1ubuntu11.98:6.9.10.23+dfsg-2.1ubuntu11.9
imagemagickimagemagick>= 0 < 8:6.9.10.23+dfsg-2.1ubuntu11.108:6.9.10.23+dfsg-2.1ubuntu11.10
imagemagickimagemagick>= 0 < 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.58:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
imagemagickimagemagick>= 0 < 8:6.8.9.9-7ubuntu5.16+esm88:6.8.9.9-7ubuntu5.16+esm8
imagemagickimagemagick>= 0 < 8:6.9.7.4+dfsg-16ubuntu6.15+esm18:6.9.7.4+dfsg-16ubuntu6.15+esm1
imagemagickimagemagick>= 0 < 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+esm28:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+esm2
imagemagickimagemagick>= 6.9.10.88 < 6.9.12-146.9.12-14
imagemagickimagemagick>= 7.0.0-0 < 7.0.11-147.0.11-14
redhatenterprise_linux

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH