First published: Tue Aug 22 2023(Updated: )
A memory leak in ImageMagick 7.0.10-45 and 6.9.11-22 allows remote attackers to perform a denial of service via the "identify -help" command.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick ImageMagick | =6.9.11-22 | |
ImageMagick ImageMagick | =7.0.10-45 | |
ubuntu/imagemagick | <8:6.9.7.4+dfsg-16ubuntu6.15+ | 8:6.9.7.4+dfsg-16ubuntu6.15+ |
ubuntu/imagemagick | <8:6.7.7.10-6ubuntu3.13+ | 8:6.7.7.10-6ubuntu3.13+ |
ubuntu/imagemagick | <8:6.8.9.9-7ubuntu5.16+ | 8:6.8.9.9-7ubuntu5.16+ |
ubuntu/imagemagick | <8:6.9.11.57+dfsg-1 | 8:6.9.11.57+dfsg-1 |
ubuntu/imagemagick | <8:6.9.10.23+dfsg-2.1ubuntu11.9+ | 8:6.9.10.23+dfsg-2.1ubuntu11.9+ |
debian/imagemagick | <=8:6.9.10.23+dfsg-2.1+deb10u1<=8:6.9.10.23+dfsg-2.1+deb10u6 | 8:6.9.11.60+dfsg-1.3+deb11u2 8:6.9.11.60+dfsg-1.3+deb11u3 8:6.9.11.60+dfsg-1.6 8:6.9.11.60+dfsg-1.6+deb12u1 8:6.9.12.98+dfsg1-5 |
Fedoraproject Fedora | =38 | |
Fedoraproject Fedora | =39 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this memory leak in ImageMagick is CVE-2022-48541.
The severity of CVE-2022-48541 is high (CVSS score of 7.5).
CVE-2022-48541 affects ImageMagick versions 7.0.10-45 and 6.9.11-22.
Remote attackers can exploit CVE-2022-48541 by performing a denial of service attack using the "identify -help" command.
Yes, there are fixes available for CVE-2022-48541. Please refer to the vendor's security notice for more information.