A heap-buffer-overflow flaw was found in ImageMagick’s PushShortPixel() function of quantum-private.h file. This vulnerability is triggered when an attacker passes a specially crafted TIFF image file to ImageMagick for conversion, potentially leading to a denial of service.
2022-08-29T15:15:10.297
2024-11-21T06:40:04.640
Modified
CVSSv3.1: 5.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | imagemagick | imagemagick | < 6.9.12-44 | Yes |
Application | imagemagick | imagemagick | < 7.1.0-29 | Yes |