First published: Wed Jan 26 2022(Updated: )
A heap-based-buffer-over-read flaw was found in ImageMagick's GetPixelAlpha() function of 'pixel-accessor.h'. This vulnerability is triggered when an attacker passes a specially crafted Tagged Image File Format (TIFF) image to convert it into a PICON file format. This issue can potentially lead to a denial of service and information disclosure.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick ImageMagick | <7.1.0-20 | |
redhat/ImageMagick 7.1.0 | <20 | 20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0284 is a heap-based-buffer-over-read vulnerability found in ImageMagick's GetPixelAlpha() function.
CVE-2022-0284 affects ImageMagick versions up to and including 7.1.0-20.
CVE-2022-0284 has a severity rating of 7.1, which is considered high.
CVE-2022-0284 can be exploited by an attacker passing a specially crafted TIFF image to convert it into a PICON file format.
Yes, upgrading to a version of ImageMagick that is newer than 7.1.0-20 will fix CVE-2022-0284.