CVE-2012-0248: Medium severity imagemagick vulnerability
Published Jun 5, 2012
·Updated
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF.
Affected Software
17 affected components
ImageMagick ImageMagick<=6.7.5-7
Debian Debian Linux=6.0
Debian Debian Linux=7.0
Canonical Ubuntu Linux=10.04
Canonical Ubuntu Linux=11.04
Canonical Ubuntu Linux=11.10
Canonical Ubuntu Linux=12.04
redhat Storage=2.0
redhat Enterprise Linux Desktop=5.0
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Eus=6.2
redhat Enterprise Linux Server=5.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Server Aus=6.2
redhat Enterprise Linux Server Eus=6.2
redhat Enterprise Linux Workstation=5.0
redhat Enterprise Linux Workstation=6.0
Remediation
Event History
Jun 5, 2012
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0248?
The severity of CVE-2012-0248 is considered moderate due to its potential to cause denial of service.
2
How do I fix CVE-2012-0248?
To fix CVE-2012-0248, update ImageMagick to version 6.7.8-0 or later.
3
Which software versions are affected by CVE-2012-0248?
CVE-2012-0248 affects ImageMagick versions up to and including 6.7.5-7.
4
What happens if I encounter CVE-2012-0248?
Encountering CVE-2012-0248 may result in infinite loops and hangs when processing crafted images.
5
Is CVE-2012-0248 specific to any operating system?
CVE-2012-0248 is relevant to multiple operating systems including Debian and Ubuntu, in addition to different Red Hat products.