CVE-2022-48541: High severity imagemagick vulnerability
Published Aug 22, 2023
·Updated
A memory leak in ImageMagick 7.0.10-45 and 6.9.11-22 allows remote attackers to perform a denial of service via the "identify -help" command.
Affected Software
10 affected componentsFixes available
ubuntu/imagemagick<8:6.9.7.4+dfsg-16ubuntu6.15+
8:6.9.7.4+dfsg-16ubuntu6.15+
ubuntu/imagemagick<8:6.7.7.10-6ubuntu3.13+
8:6.7.7.10-6ubuntu3.13+
ubuntu/imagemagick<8:6.8.9.9-7ubuntu5.16+
8:6.8.9.9-7ubuntu5.16+
ubuntu/imagemagick<8:6.9.11.57+dfsg-1
8:6.9.11.57+dfsg-1
ubuntu/imagemagick<8:6.9.10.23+dfsg-2.1ubuntu11.9+
8:6.9.10.23+dfsg-2.1ubuntu11.9+
debian/imagemagick<=8:6.9.10.23+dfsg-2.1+deb10u1, <=8:6.9.10.23+dfsg-2.1+deb10u6
8:6.9.11.60+dfsg-1.3+deb11u28:6.9.11.60+dfsg-1.3+deb11u38:6.9.11.60+dfsg-1.68:6.9.11.60+dfsg-1.6+deb12u18:6.9.12.98+dfsg1-5
ImageMagick=6.9.11-22
ImageMagick=7.0.10-45
fedoraproject fedora=38
fedoraproject fedora=39
Event History
Aug 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Feb 1, 2024
Data Sourced
via Launchpad·12:19 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this memory leak in ImageMagick?
The vulnerability ID for this memory leak in ImageMagick is CVE-2022-48541.
2
What is the severity of CVE-2022-48541?
The severity of CVE-2022-48541 is high (CVSS score of 7.5).
3
How does CVE-2022-48541 affect ImageMagick?
CVE-2022-48541 affects ImageMagick versions 7.0.10-45 and 6.9.11-22.
4
How can remote attackers exploit CVE-2022-48541?
Remote attackers can exploit CVE-2022-48541 by performing a denial of service attack using the "identify -help" command.
5
Is there a fix available for CVE-2022-48541?
Yes, there are fixes available for CVE-2022-48541. Please refer to the vendor's security notice for more information.