CVE-2023-34151
published 2023-05-30CVE-2023-34151: A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other coders…
PriorityP419medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
1.02%
59.4th percentile
A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other coders (recurring bugs of CVE-2022-32546).
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | imagemagick | < imagemagick 8:6.9.11.60+dfsg-1.6+deb12u1 (bookworm) | imagemagick 8:6.9.11.60+dfsg-1.6+deb12u1 (bookworm) |
| fedoraproject | extra_packages_for_enterprise_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| imagemagick | imagemagick | < 7.1.1-11 | 7.1.1-11 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.3+deb11u3 | 8:6.9.11.60+dfsg-1.3+deb11u3 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.6+deb12u1 | 8:6.9.11.60+dfsg-1.6+deb12u1 |
| imagemagick | imagemagick | >= 0 < 8:6.9.12.98+dfsg1-2 | 8:6.9.12.98+dfsg1-2 |
| imagemagick | imagemagick | >= 0 < 8:6.9.12.98+dfsg1-2 | 8:6.9.12.98+dfsg1-2 |
| imagemagick | imagemagick | >= 0 < 8:6.9.10.23+dfsg-2.1ubuntu11.9 | 8:6.9.10.23+dfsg-2.1ubuntu11.9 |
| imagemagick | imagemagick | >= 0 < 8:6.9.10.23+dfsg-2.1ubuntu11.11 | 8:6.9.10.23+dfsg-2.1ubuntu11.11 |
| imagemagick | imagemagick | >= 0 < 8:6.9.10.23+dfsg-2.1ubuntu11.10 | 8:6.9.10.23+dfsg-2.1ubuntu11.10 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5 | 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5 |
| imagemagick | imagemagick | >= 0 < 8:6.8.9.9-7ubuntu5.16+esm8 | 8:6.8.9.9-7ubuntu5.16+esm8 |
| imagemagick | imagemagick | >= 0 < 8:6.9.7.4+dfsg-16ubuntu6.15+esm1 | 8:6.9.7.4+dfsg-16ubuntu6.15+esm1 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+esm2 | 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+esm2 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ImageMagick regression
vendor_ubuntu·2025-04-16·CVSS 5.5
CVE-2023-34151 [MEDIUM] ImageMagick regression
Title: ImageMagick regression
Summary: USN-6200-2 introduced a regression in ImageMagick.
USN-6200-2 fixed a vulnerability in ImageMagick. It was discovered that the
fix for CVE-2023-34151 was incomplete. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that ImageMagick incorrectly handled memory under
certain circumstances. If a user were tricked into opening a specially
crafted image file, an attacker could possibly exploit this issue to
cause a denial of service or other unspecified impact. (CVE-2023-34151)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2024-07-25·CVSS 7.8
CVE-2023-1289 [HIGH] ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: Several security issues were fixed in ImageMagick.
USN-6200-1 fixed vulnerabilities in ImageMagick. Unfortunately these fixes were
incomplete for Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. This update fixes the
problem.
Original advisory details:
It was discovered that ImageMagick incorrectly handled the "-authenticate"
option for password-protected PDF files. An attacker could possibly use
this issue to inject additional shell commands and perform arbitrary code
execution. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-29599)
It was discovered that ImageMagick incorrectly handled certain values
when processing PDF files. If a user or automated system using ImageMagick
were tricked into opening a specially crafted PDF file, an attacker co
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2023-07-04·CVSS 7.8
CVE-2023-1289 [HIGH] ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: Several security issues were fixed in ImageMagick.
It was discovered that ImageMagick incorrectly handled the "-authenticate"
option for password-protected PDF files. An attacker could possibly use
this issue to inject additional shell commands and perform arbitrary code
execution. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-29599)
It was discovered that ImageMagick incorrectly handled certain values
when processing PDF files. If a user or automated system using ImageMagick
were tricked into opening a specially crafted PDF file, an attacker could
exploit this to cause a denial of service. This issue only affected Ubuntu
20.04 LTS. (CVE-2021-20224)
Zhang Xiaohui discovered that ImageMagick incorrectly handled certain
values when proce
Red Hat
ImageMagick: Undefined behaviors of casting double to size_t in svg, mvg and other coders
vendor_redhat·2023-05-29·CVSS 7.8
CVE-2023-34151 [HIGH] CWE-190 ImageMagick: Undefined behaviors of casting double to size_t in svg, mvg and other coders
ImageMagick: Undefined behaviors of casting double to size_t in svg, mvg and other coders
A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other coders (recurring bugs of CVE-2022-32546).
A vulnerability was found in ImageMagick. This issue occurs as an undefined behavior, casting double to size_t in svg, mvg and other coders.
Package: ImageMagick (Red Hat Enterprise Linux 6) - Out of support scope
Package: ImageMagick (Red Hat Enterprise Linux 7) - Out of support scope
Debian
CVE-2023-34151: imagemagick - A vulnerability was found in ImageMagick. This security flaw ouccers as an undef...
vendor_debian·2023·CVSS 7.8
CVE-2023-34151 [HIGH] CVE-2023-34151: imagemagick - A vulnerability was found in ImageMagick. This security flaw ouccers as an undef...
A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other coders (recurring bugs of CVE-2022-32546).
Scope: local
bookworm: resolved (fixed in 8:6.9.11.60+dfsg-1.6+deb12u1)
bullseye: resolved (fixed in 8:6.9.11.60+dfsg-1.3+deb11u3)
forky: resolved (fixed in 8:6.9.12.98+dfsg1-2)
sid: resolved (fixed in 8:6.9.12.98+dfsg1-2)
trixie: resolved (fixed in 8:6.9.12.98+dfsg1-2)
OSV
imagemagick regression
osv·2025-04-16·CVSS 5.5
CVE-2023-34151 [MEDIUM] imagemagick regression
imagemagick regression
USN-6200-2 fixed a vulnerability in ImageMagick. It was discovered that the
fix for CVE-2023-34151 was incomplete. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that ImageMagick incorrectly handled memory under
certain circumstances. If a user were tricked into opening a specially
crafted image file, an attacker could possibly exploit this issue to
cause a denial of service or other unspecified impact. (CVE-2023-34151)
OSV
imagemagick vulnerabilities
osv·2024-07-25·CVSS 7.8
[HIGH] imagemagick vulnerabilities
imagemagick vulnerabilities
USN-6200-1 fixed vulnerabilities in ImageMagick. Unfortunately these fixes were
incomplete for Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. This update fixes the
problem.
Original advisory details:
It was discovered that ImageMagick incorrectly handled the "-authenticate"
option for password-protected PDF files. An attacker could possibly use
this issue to inject additional shell commands and perform arbitrary code
execution. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-29599)
It was discovered that ImageMagick incorrectly handled certain values
when processing PDF files. If a user or automated system using ImageMagick
were tricked into opening a specially crafted PDF file, an attacker could
exploit this to cause a denial of service. This issue only affec
OSV
imagemagick vulnerabilities
osv·2023-07-04·CVSS 7.8
CVE-2020-29599 [HIGH] imagemagick vulnerabilities
imagemagick vulnerabilities
It was discovered that ImageMagick incorrectly handled the "-authenticate"
option for password-protected PDF files. An attacker could possibly use
this issue to inject additional shell commands and perform arbitrary code
execution. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-29599)
It was discovered that ImageMagick incorrectly handled certain values
when processing PDF files. If a user or automated system using ImageMagick
were tricked into opening a specially crafted PDF file, an attacker could
exploit this to cause a denial of service. This issue only affected Ubuntu
20.04 LTS. (CVE-2021-20224)
Zhang Xiaohui discovered that ImageMagick incorrectly handled certain
values when processing image data. If a user or automated system using
ImageMagick we
GHSA
GHSA-cm6m-2vvh-cxc6: A vulnerability was found in ImageMagick
ghsa_unreviewed·2023-05-31·CVSS 7.8
CVE-2023-34151 [HIGH] CWE-190 GHSA-cm6m-2vvh-cxc6: A vulnerability was found in ImageMagick
A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other coders (recurring bugs of CVE-2022-32546).
OSV
CVE-2023-34151: A vulnerability was found in ImageMagick
osv·2023-05-30·CVSS 7.8
CVE-2023-34151 [HIGH] CVE-2023-34151: A vulnerability was found in ImageMagick
A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other coders (recurring bugs of CVE-2022-32546).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2023-34151https://bugzilla.redhat.com/show_bug.cgi?id=2210657https://github.com/ImageMagick/ImageMagick/issues/6341https://lists.debian.org/debian-lts-announce/2024/02/msg00007.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UFQJCYJ23HWHNDOVKBHZQ7HCXXL6MM3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2ZUHZXQ2C3JZYKPW4XHCMVVL467MA2V/https://access.redhat.com/security/cve/CVE-2023-34151https://bugzilla.redhat.com/show_bug.cgi?id=2210657https://github.com/ImageMagick/ImageMagick/issues/6341https://lists.debian.org/debian-lts-announce/2024/02/msg00007.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UFQJCYJ23HWHNDOVKBHZQ7HCXXL6MM3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2ZUHZXQ2C3JZYKPW4XHCMVVL467MA2V/
2023-05-30
Published