CVE-2022-32546: Integer Overflow
A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned long' at coders/pcl.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior.
Other sources
In ImageMagick version < 7.1.0-29, there is an outside the range of representable values of type 'unsigned long' at coders/pcl.c.
References: https://github.com/ImageMagick/ImageMagick/issues/4985 https://github.com/ImageMagick/ImageMagick/pull/4986
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-32546?
CVE-2022-32546 is a vulnerability found in ImageMagick that leads to undefined behavior and a negative impact on application availability.
What is the severity of CVE-2022-32546?
The severity of CVE-2022-32546 is high with a CVSS score of 7.8.
How does CVE-2022-32546 affect ImageMagick?
CVE-2022-32546 affects ImageMagick by causing an outside the range of representable values of type 'unsigned long' at coders/pcl.c, when crafted or untrusted input is processed.
Which versions of ImageMagick are affected by CVE-2022-32546?
The affected versions of ImageMagick include 8:6.9.11.60+dfsg-1.3ubuntu0.22.10.1, 8:6.9.11.60+dfsg-1.3ubuntu1, 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+, 8:6.9.7.4+dfsg-16ubuntu6.14, and 8:6.9.10.23+dfsg-2.1ubuntu11.9.
How can I fix CVE-2022-32546 in ImageMagick?
To fix CVE-2022-32546 in ImageMagick, update to the latest versions available: 8:6.9.11.60+dfsg-1.6 for Debian and 8:6.9.11.60+dfsg-1.3ubuntu1 for Ubuntu.