REDHAT-BUG-1344271: Low severity imagemagick vulnerability
An error was discovered in the ImageMagick -split functionality. Processing a specially crafted image using this functionality could lead to an application crash.
External references:
http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=28466 http://seclists.org/oss-sec/2016/q2/459
Patch:
http://git.imagemagick.org/repos/ImageMagick/commit/e00cf211070e7f150a3da77932b8620c89bb9225
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1344271?
The severity of REDHAT-BUG-1344271 is high due to the potential for application crashes when processing specially crafted images.
How do I fix REDHAT-BUG-1344271?
To fix REDHAT-BUG-1344271, update to the latest version of ImageMagick that addresses this vulnerability.
What is the cause of the vulnerability REDHAT-BUG-1344271?
The vulnerability REDHAT-BUG-1344271 is caused by an error in ImageMagick's -split functionality when processing specially crafted images.
Which versions of ImageMagick are affected by REDHAT-BUG-1344271?
REDHAT-BUG-1344271 may affect multiple versions of ImageMagick prior to the security fix, so all users should verify their installed version.
Can REDHAT-BUG-1344271 be exploited remotely?
Yes, REDHAT-BUG-1344271 can potentially be exploited remotely if an attacker can entice a user into processing a crafted image.