First published: Tue May 31 2022(Updated: )
A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned long' at coders/pcl.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ImageMagick 6.9.12 | <44 | 44 |
redhat/ImageMagick 7.1.0 | <29 | 29 |
debian/imagemagick | 8:6.9.11.60+dfsg-1.3+deb11u4 8:6.9.11.60+dfsg-1.3+deb11u3 8:6.9.11.60+dfsg-1.6+deb12u2 8:6.9.11.60+dfsg-1.6+deb12u1 8:7.1.1.43+dfsg1-1 | |
ImageMagick ImageMagick | <6.9.12-44 | |
ImageMagick ImageMagick | >=7.1.0<7.1.0-29 | |
Fedora EPEL | =8.0 | |
Fedora | =36 | |
Red Hat Enterprise Linux | =6.0 | |
Red Hat Enterprise Linux | =7.0 | |
ImageMagick | <6.9.12-44 | |
ImageMagick | >=7.1.0<7.1.0-29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-32546 is a vulnerability found in ImageMagick that leads to undefined behavior and a negative impact on application availability.
The severity of CVE-2022-32546 is high with a CVSS score of 7.8.
CVE-2022-32546 affects ImageMagick by causing an outside the range of representable values of type 'unsigned long' at coders/pcl.c, when crafted or untrusted input is processed.
The affected versions of ImageMagick include 8:6.9.11.60+dfsg-1.3ubuntu0.22.10.1, 8:6.9.11.60+dfsg-1.3ubuntu1, 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+, 8:6.9.7.4+dfsg-16ubuntu6.14, and 8:6.9.10.23+dfsg-2.1ubuntu11.9.
To fix CVE-2022-32546 in ImageMagick, update to the latest versions available: 8:6.9.11.60+dfsg-1.6 for Debian and 8:6.9.11.60+dfsg-1.3ubuntu1 for Ubuntu.