CVE-2012-0260: Medium severity imagemagick vulnerability
Published Jun 5, 2012
·Updated
The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (memory consumption) via a JPEG image with a crafted sequence of restart markers.
Affected Software
17 affected components
ImageMagick ImageMagick<6.7.6-3
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=12.10
Canonical Ubuntu Linux=13.10
Debian Debian Linux=6.0
redhat Storage=2.0
redhat Enterprise Linux Aus=6.2
redhat Enterprise Linux Desktop=5.0
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Eus=6.2
redhat Enterprise Linux Server=5.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Server Eus=6.2
redhat Enterprise Linux Workstation=5.0
redhat Enterprise Linux Workstation=6.0
openSUSE openSUSE=11.4
openSUSE openSUSE=12.1
Remediation
Patch Available
Event History
Jun 5, 2012
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0260?
CVE-2012-0260 has a severity level classified as high due to its ability to cause denial of service.
2
How do I fix CVE-2012-0260?
To fix CVE-2012-0260, update ImageMagick to version 6.7.6-3 or later.
3
What type of attack is possible with CVE-2012-0260?
CVE-2012-0260 allows remote attackers to launch a denial of service attack through crafted JPEG images.
4
Which software is affected by CVE-2012-0260?
CVE-2012-0260 affects multiple versions of ImageMagick prior to 6.7.6-3.
5
On which operating systems does CVE-2012-0260 impact users?
CVE-2012-0260 affects users on several operating systems, including Ubuntu, Debian, and Red Hat distributions.