CVE-2023-34151: Integer Overflow
A vulnerability was found in ImageMagick. This issue occurs as an undefined behavior, casting double to sizet in svg, mvg and other coders.
Other sources
A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to sizet in svg, mvg and other coders (recurring bugs of CVE-2022-32546).
Undefined behaviors of casting double to sizet in svg, mvg and other coders (recurring bugs of CVE-2022-32546) https://github.com/ImageMagick/ImageMagick/issues/6341
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/imagemagickto a version that resolves this vulnerability.Fixed in 8:6.9.11.60+dfsg-1.3+deb11u4Fixed in 8:6.9.11.60+dfsg-1.3+deb11u5Fixed in 8:6.9.11.60+dfsg-1.6+deb12u2Fixed in 8:6.9.11.60+dfsg-1.6+deb12u1Fixed in 8:7.1.1.43+dfsg1-1Fixed in 8:7.1.1.47+dfsg1-1
Event History
Frequently Asked Questions
What is the severity of CVE-2023-34151?
The severity of CVE-2023-34151 is medium.
How does the vulnerability occur in ImageMagick?
The vulnerability in ImageMagick occurs as undefined behavior of casting double to size_t in svg, mvg, and other coders.
Which software versions are affected by CVE-2023-34151?
ImageMagick versions up to 7.1.1.11, Fedoraproject Extra Packages For Enterprise Linux 8.0, Fedoraproject Fedora 37 and 38, Redhat Enterprise Linux 6.0 and 7.0 are affected by CVE-2023-34151.
Where can I find more information about CVE-2023-34151?
You can find more information about CVE-2023-34151 on the CVE website (https://www.cve.org/CVERecord?id=CVE-2023-34151) and the NVD website (https://nvd.nist.gov/vuln/detail/CVE-2023-34151).
How do I fix the vulnerability in ImageMagick?
To fix the vulnerability in ImageMagick, it is recommended to update to a version that includes the security patch.