PT-2012-2445 · Imagemagick+3 · Imagemagick+3

Aleksis Kauppinen

+3

·

Published

2012-05-07

·

Updated

2020-07-31

·

CVE-2012-0259

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 6.7.6-3
Description The issue allows remote attackers to cause a denial of service (crash) via a zero value in the component count of an EXIF XResolution tag in a JPEG file, which triggers an out-of-bounds read. This occurs due to a problem in the GetEXIFProperty function in magick/property.c.
Recommendations For versions prior to 6.7.6-3, update to version 6.7.6-3 or later to resolve the issue. As a temporary workaround, consider restricting the processing of JPEG files with potentially malformed EXIF tags until a patch is applied.

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2012_0544
CVE-2012-0259
DSA-2462-1
RHSA-2012:0544
RHSA-2012_0544

Affected Products

Centos
Imagemagick
Red Hat
Suse