CVE-2022-3213Improper Restriction of Operations within the Bounds of a Memory Buffer in Imagemagick

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 90.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 19
Latest updateSep 20

Description

A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lead to undefined behavior or a crash causing a denial of service.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

debiandebian/imagemagick< imagemagick 8:6.9.11.60+dfsg-1.6+deb12u1 (bookworm)
NVDimagemagick/imagemagick7.1.0-07.1.0-47+1
Debianimagemagick/imagemagick< 8:6.9.11.60+dfsg-1.3+deb11u3+3
CVEListV5imagemagick/imagemagickFixed in ImageMagick 7.1.0-47, ImageMagick 6.9.12-62

Also affects: Fedora 35, 36, 37

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rvv6-3f7f-jg4m: A heap buffer overflow issue was found in ImageMagick2022-09-20
OSV
CVE-2022-3213: A heap buffer overflow issue was found in ImageMagick2022-09-19

📋Vendor Advisories

2
Red Hat
ImageMagick: heap buffer overflow while processing a malformed TIFF file2022-08-27
Debian
CVE-2022-3213: imagemagick - A heap buffer overflow issue was found in ImageMagick. When an application proce...2022