First published: Thu Mar 09 2023(Updated: )
A specially created SVG file that loads by itself and make segmentation fault. Remote attackers can take advantage of this vulnerability to cause a denial of service of the generated SVG file. It seems that this error affects a lot of websites and causes a generating trash files in /tmp when uploading this PC file to the server. I think it's better to check the file descriptor coming from itself before executing read(). Refeners: Security issues: <a href="https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-j96m-mjp6-99xr">https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-j96m-mjp6-99xr</a> Fix commit: <a href="https://github.com/ImageMagick/ImageMagick/commit/c5b23cbf2119540725e6dc81f4deb25798ead6a4">https://github.com/ImageMagick/ImageMagick/commit/c5b23cbf2119540725e6dc81f4deb25798ead6a4</a>
Credit: secalert@redhat.com secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ImageMagick 7.1.1 | <0 | 0 |
debian/imagemagick | 8:6.9.11.60+dfsg-1.3+deb11u4 8:6.9.11.60+dfsg-1.3+deb11u3 8:6.9.11.60+dfsg-1.6+deb12u2 8:6.9.11.60+dfsg-1.6+deb12u1 8:7.1.1.43+dfsg1-1 | |
ImageMagick ImageMagick | <7.1.1-0 | |
Fedoraproject Extra Packages For Enterprise Linux | =8.0 | |
Fedoraproject Extra Packages For Enterprise Linux | =9.0 | |
Fedoraproject Fedora | =36 | |
Fedoraproject Fedora | =37 | |
Red Hat Enterprise Linux | =8.0 | |
Red Hat Enterprise Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1289 is a vulnerability discovered in ImageMagick where a specially created SVG file leads to a segmentation fault, resulting in a denial of service.
CVE-2023-1289 has a severity rating of 5.5 out of 10.
Ubuntu ImageMagick versions 8:6.9.10.23+dfsg-2.1ubuntu11.9, 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+, 8:6.9.11.60+dfsg-1.3ubuntu0.22.10.5, 7.1.1-0, 8:6.9.11.60+dfsg-1.6ubuntu0.23.04.1, and 8:6.9.11.60+dfsg-1.6ubuntu1 are affected.
Apply the appropriate remedy provided by Ubuntu for the affected ImageMagick versions.
More information about CVE-2023-1289 can be found on the MITRE CVE database and the ImageMagick GitHub security advisories.