CVE-2012-1610: Integer Overflow
Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-4 allows remote attackers to cause a denial of service (out-of-bounds read) via a large component count for certain EXIF tags in a JPEG image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0259.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1610?
CVE-2012-1610 has a severity that can lead to a denial of service due to an integer overflow issue in ImageMagick.
How do I fix CVE-2012-1610?
To fix CVE-2012-1610, update ImageMagick to version 6.7.6-4 or later.
What types of attacks can exploit CVE-2012-1610?
CVE-2012-1610 can be exploited by attackers using specially crafted JPEG images with a large EXIF component count.
Which software is affected by CVE-2012-1610?
CVE-2012-1610 affects various versions of ImageMagick prior to 6.7.6-4 and certain Linux distributions using vulnerable ImageMagick versions.
Is there a workaround for CVE-2012-1610?
There is no formal workaround for CVE-2012-1610; the best approach is to apply the latest updates to ImageMagick.