CVE-2023-3195Stack-based Buffer Overflow in Imagemagick

Severity
5.5MEDIUMNVD
OSV7.8
EPSS
0.0%
top 91.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 16
Latest updateJul 25

Description

A stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. This flaw allows an attacker to trick the user into opening a specially crafted malicious tiff file, causing an application to crash, resulting in a denial of service.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

debiandebian/imagemagick< imagemagick 8:6.9.12.98+dfsg1-2 (forky)
NVDimagemagick/imagemagick7.1.1-07.1.1-10+1
Debianimagemagick/imagemagick< 8:6.9.12.98+dfsg1-2+1
Ubuntuimagemagick/imagemagick< 8:6.9.10.23+dfsg-2.1ubuntu11.9+5
CVEListV5imagemagick/imagemagickFixed in ImageMagick 6.9.12-26, ImageMagick 7.1.0-11

Also affects: Fedora 37, 38

Patches

🔴Vulnerability Details

4
OSV
imagemagick vulnerabilities2024-07-25
OSV
imagemagick vulnerabilities2023-07-04
GHSA
GHSA-4f76-c3p6-5cgx: A stack-based buffer overflow issue was found in ImageMagick's coders/tiff2023-06-16
OSV
CVE-2023-3195: A stack-based buffer overflow issue was found in ImageMagick's coders/tiff2023-06-16

📋Vendor Advisories

4
Ubuntu
ImageMagick vulnerabilities2024-07-25
Ubuntu
ImageMagick vulnerabilities2023-07-04
Red Hat
ImageMagick: stack overflow in coders/tiff.c while parsing malicious tiff file2023-05-29
Debian
CVE-2023-3195: imagemagick - A stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. Th...2023