First published: Thu Jun 09 2016(Updated: )
An error was discovered in the ImageMagick -split functionality. Processing a specially crafted image using this functionality could lead to an application crash. External references: <a href="http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=28466">http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=28466</a> <a href="http://seclists.org/oss-sec/2016/q2/459">http://seclists.org/oss-sec/2016/q2/459</a> Patch: <a href="http://git.imagemagick.org/repos/ImageMagick/commit/e00cf211070e7f150a3da77932b8620c89bb9225">http://git.imagemagick.org/repos/ImageMagick/commit/e00cf211070e7f150a3da77932b8620c89bb9225</a>
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1344271 is high due to the potential for application crashes when processing specially crafted images.
To fix REDHAT-BUG-1344271, update to the latest version of ImageMagick that addresses this vulnerability.
The vulnerability REDHAT-BUG-1344271 is caused by an error in ImageMagick's -split functionality when processing specially crafted images.
REDHAT-BUG-1344271 may affect multiple versions of ImageMagick prior to the security fix, so all users should verify their installed version.
Yes, REDHAT-BUG-1344271 can potentially be exploited remotely if an attacker can entice a user into processing a crafted image.