First published: Fri Jun 18 2021(Updated: )
A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ImageMagick 7.0.11 | <14 | 14 |
ubuntu/imagemagick | <8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+ | 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+ |
ubuntu/imagemagick | <8:6.9.11.60+dfsg-1.3ubuntu0.22.10.5 | 8:6.9.11.60+dfsg-1.3ubuntu0.22.10.5 |
ubuntu/imagemagick | <8:6.9.11.60+dfsg-1.6ubuntu0.23.04.1 | 8:6.9.11.60+dfsg-1.6ubuntu0.23.04.1 |
ubuntu/imagemagick | <8:6.9.11.60+dfsg-1.6ubuntu1 | 8:6.9.11.60+dfsg-1.6ubuntu1 |
>=6.9.10.88<6.9.12-14 | ||
>=7.0.0-0<7.0.11-14 | ||
=34 | ||
=8.0 | ||
ImageMagick ImageMagick | >=6.9.10.88<6.9.12-14 | |
ImageMagick ImageMagick | >=7.0.0-0<7.0.11-14 | |
Fedoraproject Fedora | =34 | |
Redhat Enterprise Linux | =8.0 | |
debian/imagemagick | <=8:6.9.11.60+dfsg-1.3+deb11u1<=8:6.9.11.60+dfsg-1.6 | 8:6.9.10.23+dfsg-2.1+deb10u1 8:6.9.10.23+dfsg-2.1+deb10u5 8:6.9.12.98+dfsg1-5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3610 is a heap-based buffer overflow vulnerability found in ImageMagick.
CVE-2021-3610 has a severity value of 7.5, which is high.
Versions of ImageMagick prior to 7.0.11-14 and 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+ are affected.
To fix CVE-2021-3610, update ImageMagick to version 7.0.11-14 or 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+.
You can find more information about CVE-2021-3610 at the following references: [1](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3610), [2](https://marc.info/?l=oss-security&m=168538363229922), [3](https://ubuntu.com/security/notices/USN-6200-1).