First published: Sat Jul 28 2012(Updated: )
The Magick_png_malloc function in coders/png.c in ImageMagick 6.7.8 and earlier does not use the proper variable type for the allocation size, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG file that triggers incorrect memory allocation.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick ImageMagick | =6.7.8-6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3437 is classified as a medium severity vulnerability due to its potential to cause denial of service.
To fix CVE-2012-3437, upgrade ImageMagick to version 6.7.8-7 or later.
CVE-2012-3437 is a memory allocation vulnerability that can lead to application crashes.
Yes, CVE-2012-3437 can be exploited remotely through crafted PNG files.
CVE-2012-3437 affects ImageMagick versions 6.7.8 and earlier.