CVE-2022-1114
published 2022-04-29CVE-2022-1114: A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm.c file. This vulnerability is triggered when an attacker passes a…
PriorityP427high7.1CVSS 3.1
AVLACLPRNUIRSUCHINAH
EPSS
1.15%
63.6th percentile
A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm.c file. This vulnerability is triggered when an attacker passes a specially crafted DICOM image file to ImageMagick for conversion, potentially leading to information disclosure and a denial of service.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imagemagick | < imagemagick 8:6.9.11.60+dfsg-1.5 (bookworm) | imagemagick 8:6.9.11.60+dfsg-1.5 (bookworm) |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.3+deb11u2 | 8:6.9.11.60+dfsg-1.3+deb11u2 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.5 | 8:6.9.11.60+dfsg-1.5 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.5 | 8:6.9.11.60+dfsg-1.5 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.5 | 8:6.9.11.60+dfsg-1.5 |
| imagemagick | imagemagick | >= 0 < 8:6.9.7.4+dfsg-16ubuntu6.14 | 8:6.9.7.4+dfsg-16ubuntu6.14 |
| imagemagick | imagemagick | >= 0 < 8:6.7.7.10-6ubuntu3.13+esm3 | 8:6.7.7.10-6ubuntu3.13+esm3 |
| imagemagick | imagemagick | >= 0 < 8:6.8.9.9-7ubuntu5.16+esm5 | 8:6.8.9.9-7ubuntu5.16+esm5 |
| imagemagick | imagemagick | >= 0 < 8:6.9.10.23+dfsg-2.1ubuntu11.4+esm1 | 8:6.9.10.23+dfsg-2.1ubuntu11.4+esm1 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.1+esm1 | 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.1+esm1 |
| imagemagick | imagemagick | >= 6.0 < 6.9.12-43 | 6.9.12-43 |
| imagemagick | imagemagick | >= 7.0.0-0 < 7.1.0-28 | 7.1.0-28 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2022-11-24·CVSS 5.5
CVE-2021-20313 [MEDIUM] ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: Several security issues were fixed in ImageMagick.
USN-5736-1 fixed vulnerabilities in ImageMagick. This update provides the
corresponding updates for Ubuntu 20.04 ESM and Ubuntu 22.04 ESM. One of the
issues, CVE-2021-20224, only affected Ubuntu 20.04 ESM, while
CVE-2021-20245, CVE-2021-3574, CVE-2021-4219 and CVE-2022-1114 only
affected Ubuntu 22.04 ESM.
Original advisory details:
It was discovered that ImageMagick incorrectly handled certain values
when processing PDF files. If a user or automated system using ImageMagick
were tricked into opening a specially crafted PDF file, an attacker could
exploit this to cause a denial of service. This issue only affected Ubuntu
14.04 ESM, Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2021-20224)
Zhang
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2022-11-24·CVSS 5.5
CVE-2021-20313 [MEDIUM] ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: Several security issues were fixed in ImageMagick.
It was discovered that ImageMagick incorrectly handled certain values
when processing PDF files. If a user or automated system using ImageMagick
were tricked into opening a specially crafted PDF file, an attacker could
exploit this to cause a denial of service. This issue only affected Ubuntu
14.04 ESM, Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2021-20224)
Zhang Xiaohui discovered that ImageMagick incorrectly handled certain
values when processing image data. If a user or automated system using
ImageMagick were tricked into opening a specially crafted image, an
attacker could exploit this to cause a denial of service. This issue only
affected Ubuntu 18.04 LTS and Ubuntu 22.10. (CVE-2021-2024
Red Hat
ImageMagick: heap-use-after-free in RelinquishDCMInfo of dcm.c
vendor_redhat·2022-03-16·CVSS 7.1
CVE-2022-1114 [HIGH] CWE-416 ImageMagick: heap-use-after-free in RelinquishDCMInfo of dcm.c
ImageMagick: heap-use-after-free in RelinquishDCMInfo of dcm.c
A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm.c file. This vulnerability is triggered when an attacker passes a specially crafted DICOM image file to ImageMagick for conversion, potentially leading to information disclosure and a denial of service.
A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm.c file. This vulnerability is triggered when an attacker passes a specially crafted DICOM image file to ImageMagick for conversion, potentially leading to information disclosure and a denial of service.
Statement: Versions of ImageMagick shipped with Red Hat Enterprise Linux 6, 7 are not affected, because vulnerable code is not present in our code-b
Debian
CVE-2022-1114: imagemagick - A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() functi...
vendor_debian·2022·CVSS 7.1
CVE-2022-1114 [HIGH] CVE-2022-1114: imagemagick - A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() functi...
A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm.c file. This vulnerability is triggered when an attacker passes a specially crafted DICOM image file to ImageMagick for conversion, potentially leading to information disclosure and a denial of service.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.60+dfsg-1.5)
bullseye: resolved (fixed in 8:6.9.11.60+dfsg-1.3+deb11u2)
forky: resolved (fixed in 8:6.9.11.60+dfsg-1.5)
sid: resolved (fixed in 8:6.9.11.60+dfsg-1.5)
trixie: resolved (fixed in 8:6.9.11.60+dfsg-1.5)
OSV
imagemagick vulnerabilities
osv·2022-11-24·CVSS 5.5
CVE-2021-20224 [MEDIUM] imagemagick vulnerabilities
imagemagick vulnerabilities
USN-5736-1 fixed vulnerabilities in ImageMagick. This update provides the
corresponding updates for Ubuntu 20.04 ESM and Ubuntu 22.04 ESM. One of the
issues, CVE-2021-20224, only affected Ubuntu 20.04 ESM, while
CVE-2021-20245, CVE-2021-3574, CVE-2021-4219 and CVE-2022-1114 only
affected Ubuntu 22.04 ESM.
Original advisory details:
It was discovered that ImageMagick incorrectly handled certain values
when processing PDF files. If a user or automated system using ImageMagick
were tricked into opening a specially crafted PDF file, an attacker could
exploit this to cause a denial of service. This issue only affected Ubuntu
14.04 ESM, Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2021-20224)
Zhang Xiaohui discovered that ImageMagick incorrectly handled certain
val
OSV
imagemagick vulnerabilities
osv·2022-11-24·CVSS 5.5
CVE-2021-20224 [MEDIUM] imagemagick vulnerabilities
imagemagick vulnerabilities
It was discovered that ImageMagick incorrectly handled certain values
when processing PDF files. If a user or automated system using ImageMagick
were tricked into opening a specially crafted PDF file, an attacker could
exploit this to cause a denial of service. This issue only affected Ubuntu
14.04 ESM, Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2021-20224)
Zhang Xiaohui discovered that ImageMagick incorrectly handled certain
values when processing image data. If a user or automated system using
ImageMagick were tricked into opening a specially crafted image, an
attacker could exploit this to cause a denial of service. This issue only
affected Ubuntu 18.04 LTS and Ubuntu 22.10. (CVE-2021-20241)
Zhang Xiaohui discovered that ImageMagick incorrectly handled ce
GHSA
GHSA-rhcm-mpjw-m6hf: A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm
ghsa_unreviewed·2022-04-30
CVE-2022-1114 [HIGH] CWE-416 GHSA-rhcm-mpjw-m6hf: A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm
A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm.c file. This vulnerability is triggered when an attacker passes a specially crafted DICOM image file to ImageMagick for conversion, potentially leading to information disclosure and a denial of service.
OSV
CVE-2022-1114: A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm
osv·2022-04-29·CVSS 7.1
CVE-2022-1114 [HIGH] CVE-2022-1114: A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm
A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm.c file. This vulnerability is triggered when an attacker passes a specially crafted DICOM image file to ImageMagick for conversion, potentially leading to information disclosure and a denial of service.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-04-29
Published