PT-2022-13094 · Unknown+2 · Imagemagick+2

R0Fm1A

+1

·

Published

2022-02-21

·

Updated

2024-06-15

·

CVE-2022-0284

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions ImageMagick (affected versions not specified)
Description A heap-based-buffer-over-read flaw was found in ImageMagick's GetPixelAlpha() function of 'pixel-accessor.h'. This issue is triggered when an attacker passes a specially crafted Tagged Image File Format (TIFF) image to convert it into a PICON file format, potentially leading to a denial of service and information disclosure.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-5309
CVE-2022-0284
MGASA-2022-0446
OPENSUSE-SU-2022:0540-1
OPENSUSE-SU-2022_0540-1
OPENSUSE-SU-2024:13263-1
SUSE-SU-2022:0540-1
SUSE-SU-2022_0540-1
SUSE-SU-2023:4634-1

Affected Products

Alt Linux
Imagemagick
Suse