PT-2022-7374 · Unknown+2 · Imagemagick+2

Fa1Lr4Inop

·

Published

2022-08-29

·

Updated

2024-06-15

·

CVE-2022-1115

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ImageMagick (affected versions not specified)
Description The issue is related to a heap-buffer-overflow flaw in the PushShortPixel() function, which can be triggered by a specially crafted TIFF image file. This may lead to a denial of service when the file is passed to ImageMagick for conversion. The flaw is associated with improper bounds checking within the buffer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2736
ALT-PU-2022-2832
ALT-PU-2024-2243
BDU:2024-04487
CVE-2022-1115
DSA-5628-1
OESA-2022-1903
OPENSUSE-SU-2024:13263-1

Affected Products

Alt Linux
Imagemagick
Red Os