First published: Wed Mar 23 2022(Updated: )
A heap-buffer-overflow flaw was found in ImageMagick’s PushShortPixel() function of quantum-private.h file. This vulnerability is triggered when an attacker passes a specially crafted TIFF image file to ImageMagick for conversion, potentially leading to a denial of service.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ImageMagick6 v6.9.12 | <44 | 44 |
redhat/ImageMagick7 v7.1.0 | <29 | 29 |
ImageMagick | <6.9.12-44 | |
ImageMagick | >=7.0.0-0<7.1.0-29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1115 is a heap-buffer-overflow vulnerability in ImageMagick's PushShortPixel() function.
CVE-2022-1115 affects ImageMagick when a specially crafted TIFF image file is passed for conversion, potentially leading to a denial of service.
CVE-2022-1115 has a severity rating of medium (5.5).
To fix CVE-2022-1115 in ImageMagick version 6.9.12, update to version 6.9.12-45 or later.
To fix CVE-2022-1115 in ImageMagick version 7.1.0, update to version 7.1.0-30 or later.