PT-2012-2439 · Imagemagick+3 · Imagemagick+3

Aleksis Kauppinen

+1

·

Published

2012-05-07

·

Updated

2024-06-15

·

CVE-2012-0248

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ImageMagick versions 6.7.5 and earlier
Description The issue allows remote attackers to cause a denial of service, resulting in an infinite loop and hang, by providing a crafted image. This image has an IFD that contains IOP tags, all of which reference the beginning of the IDF.
Recommendations For ImageMagick versions 6.7.5 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2012_0544
CVE-2012-0248
DSA-2427-1
OPENSUSE-SU-2024:10040-1
RHSA-2012:0544
RHSA-2012:0545
RHSA-2012_0544
RHSA-2012_0545

Affected Products

Centos
Imagemagick
Red Hat
Suse