CVE-2023-2157: Buffer Overflow
Published May 19, 2023
·Updated
A Heap Buffer Overflow issue in imagemagick, which has been fixed here: https://github.com/ImageMagick/ImageMagick/commit/9a9896fce95d09e5e47b86baccbe1ce1a2fca76b
Other sources
A heap-based buffer overflow vulnerability was found in the ImageMagick package that can lead to the application crashing.
— MITRE
Affected Software
2 affected componentsFixes available
redhat/ImageMagick 7.1.1<9
9
ImageMagick<7.1.1-9
Remediation
Patch Available
Event History
May 19, 2023
Data Sourced
via Red Hat·01:12 PM
DescriptionSeverityAffected Software
Jun 6, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-2157?
CVE-2023-2157 is a heap-based buffer overflow vulnerability found in the ImageMagick package that can lead to application crashing.
2
What is the severity of CVE-2023-2157?
The severity of CVE-2023-2157 is medium with a severity value of 5.5.
3
How does CVE-2023-2157 affect ImageMagick?
CVE-2023-2157 affects ImageMagick with version 7.1.1 up to exclusive version 9.
4
How can I fix CVE-2023-2157?
To fix CVE-2023-2157, update ImageMagick to version 9 or higher.
5
Where can I find more information about CVE-2023-2157?
More information about CVE-2023-2157 can be found at the following references: [link1], [link2], [link3].