CVE-2023-3195: Buffer Overflow
A stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. This flaw allows an attacker to trick the user into opening a specially crafted malicious tiff file, causing an application to crash, resulting in a denial of service.
Other sources
Stack overflow with crafted tiff file in ImageMagick.
Reference: https://www.openwall.com/lists/oss-security/2023/05/29/1
Upstream fix: https://github.com/ImageMagick/ImageMagick6/commit/85a370c79afeb45a97842b0959366af5236e9023 https://github.com/ImageMagick/ImageMagick/commit/f620340935777b28fa3f7b0ed7ed6bd86946934c
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/ImageMagick 6.9.12to a version that resolves this vulnerability.Fixed in 26 - Upgrade
Upgrade
redhat/ImageMagick 7.1.0to a version that resolves this vulnerability.Fixed in 11 - Upgrade
Upgrade
debian/imagemagickto a version that resolves this vulnerability.Fixed in 8:6.9.11.60+dfsg-1.3+deb11u4Fixed in 8:6.9.11.60+dfsg-1.3+deb11u5Fixed in 8:6.9.11.60+dfsg-1.6+deb12u2Fixed in 8:6.9.11.60+dfsg-1.6+deb12u1Fixed in 8:7.1.1.43+dfsg1-1Fixed in 8:7.1.1.47+dfsg1-1 - Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Patch f620340935777b28fa3f7b0ed7ed6bd86946934c - Upgrade
Upgrade
ImageMagick6to a version that resolves this vulnerability.Patch 85a370c79afeb45a97842b0959366af5236e9023
Event History
Frequently Asked Questions
What is CVE-2023-3195?
CVE-2023-3195 is a stack-based buffer overflow issue found in ImageMagick's coders/tiff.c.
How can an attacker exploit CVE-2023-3195?
An attacker can exploit CVE-2023-3195 by tricking the user into opening a specially crafted malicious tiff file.
What is the impact of CVE-2023-3195?
The impact of CVE-2023-3195 is a denial of service, causing the application to crash.
Which versions of ImageMagick are affected by CVE-2023-3195?
ImageMagick 6.9.12 up to exclusive version 26 and ImageMagick 7.1.0 up to exclusive version 11 are affected.
How do I mitigate the vulnerability?
To mitigate the vulnerability, update ImageMagick to version 6.9.12-27 or higher, or version 7.1.1-11 or higher.