Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Mageia 8 - MGASA-2023-0161 Moderate: ImageMagick Buffer Overflow Issue

mageia
Calendar Grey May 6, 2023
Dist Mageia Esm H88
Recent updates to imagemagick address a critical security vulnerability, which could lead to service interruption when processing malicious files. Discover more details!
A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c

Summary

A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service. (CVE-2023-1906)

References

- https://bugs.mageia.org/show_bug.cgi?id=31817

- https://lists.suse.com/pipermail/sle-security-updates/2023-April/014519.html

- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-35q2-86c7-9247

- https://www.cve.org/CVERecord?id=CVE-2023-1906

Resolution

SRPMS

- 8/core/imagemagick-7.1.0.62-1.1.mga8

- 8/tainted/imagemagick-7.1.0.62-1.1.mga8.tainted

Severity
medium
Lowest
Low
Medium
High
Critical

Publication date: 06 May 2023
URL: https://advisories.mageia.org/MGASA-2023-0161.html
Type: security
CVE: CVE-2023-1906

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here