First published: Fri Jun 18 2021(Updated: )
A heap-based buffer overflow vulnerability was found in ImageMagick in ReadTIFFImage() in coders/tiff.c because of an incorrect setting of the pixel array size which can lead to crash and segmentation fault. This flaw affects ImageMagick versions prior to 7.1.0-0 and 7.0.11-14. Reference and upstream patch: <a href="https://github.com/ImageMagick/ImageMagick/commit/930ff0d1a9bc42925a7856e9ea53f5fc9f318bf3">https://github.com/ImageMagick/ImageMagick/commit/930ff0d1a9bc42925a7856e9ea53f5fc9f318bf3</a>
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick ImageMagick | >=6.9.10.88<6.9.12-14 | |
ImageMagick ImageMagick | >=7.0.0-0<7.0.11-14 | |
Fedoraproject Fedora | =34 | |
Redhat Enterprise Linux | =8.0 | |
redhat/ImageMagick 7.0.11 | <14 | 14 |
debian/imagemagick | 8:6.9.11.60+dfsg-1.3+deb11u4 8:6.9.11.60+dfsg-1.3+deb11u3 8:6.9.11.60+dfsg-1.6+deb12u2 8:6.9.11.60+dfsg-1.6+deb12u1 8:7.1.1.43+dfsg1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3610 is a heap-based buffer overflow vulnerability found in ImageMagick.
CVE-2021-3610 has a severity value of 7.5, which is high.
Versions of ImageMagick prior to 7.0.11-14 and 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+ are affected.
To fix CVE-2021-3610, update ImageMagick to version 7.0.11-14 or 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+.
You can find more information about CVE-2021-3610 at the following references: [1](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3610), [2](https://marc.info/?l=oss-security&m=168538363229922), [3](https://ubuntu.com/security/notices/USN-6200-1).