CVE-2021-3610: Update CVE-2021-3610: ImageMagick
A heap-based buffer overflow vulnerability was found in ImageMagick in ReadTIFFImage() in coders/tiff.c because of an incorrect setting of the pixel array size which can lead to crash and segmentation fault. This flaw affects ImageMagick versions prior to 7.1.0-0 and 7.0.11-14.
Reference and upstream patch: https://github.com/ImageMagick/ImageMagick/commit/930ff0d1a9bc42925a7856e9ea53f5fc9f318bf3
Other sources
A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault.
— Launchpad
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-3610?
CVE-2021-3610 is a heap-based buffer overflow vulnerability found in ImageMagick.
What is the severity of CVE-2021-3610?
CVE-2021-3610 has a severity value of 7.5, which is high.
Which versions of ImageMagick are affected by CVE-2021-3610?
Versions of ImageMagick prior to 7.0.11-14 and 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+ are affected.
How do I fix CVE-2021-3610?
To fix CVE-2021-3610, update ImageMagick to version 7.0.11-14 or 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+.
Where can I find more information about CVE-2021-3610?
You can find more information about CVE-2021-3610 at the following references: [1](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3610), [2](https://marc.info/?l=oss-security&m=168538363229922), [3](https://ubuntu.com/security/notices/USN-6200-1).