ALAS2-2023-2251

Related Vulnerabilities: CVE-2022-48541  

A memory leak in ImageMagick 7.0.10-45 and 6.9.11-22 allows remote attackers to perform a denial of service via the "identify -help" command. (CVE-2022-48541)

ALAS2-2023-2251


Amazon Linux 2 Security Advisory: ALAS-2023-2251
Advisory Release Date: 2023-09-13 23:44 Pacific
Advisory Updated Date: 2023-09-20 19:40 Pacific
Severity: Medium

Issue Overview:

A memory leak in ImageMagick 7.0.10-45 and 6.9.11-22 allows remote attackers to perform a denial of service via the "identify -help" command. (CVE-2022-48541)


Affected Packages:

ImageMagick


Issue Correction:
Run yum update ImageMagick to update your system.

New Packages:
aarch64:
    ImageMagick-6.9.10.97-1.amzn2.0.8.aarch64
    ImageMagick-devel-6.9.10.97-1.amzn2.0.8.aarch64
    ImageMagick-doc-6.9.10.97-1.amzn2.0.8.aarch64
    ImageMagick-perl-6.9.10.97-1.amzn2.0.8.aarch64
    ImageMagick-c++-6.9.10.97-1.amzn2.0.8.aarch64
    ImageMagick-c++-devel-6.9.10.97-1.amzn2.0.8.aarch64
    ImageMagick-debuginfo-6.9.10.97-1.amzn2.0.8.aarch64

i686:
    ImageMagick-6.9.10.97-1.amzn2.0.8.i686
    ImageMagick-devel-6.9.10.97-1.amzn2.0.8.i686
    ImageMagick-doc-6.9.10.97-1.amzn2.0.8.i686
    ImageMagick-perl-6.9.10.97-1.amzn2.0.8.i686
    ImageMagick-c++-6.9.10.97-1.amzn2.0.8.i686
    ImageMagick-c++-devel-6.9.10.97-1.amzn2.0.8.i686
    ImageMagick-debuginfo-6.9.10.97-1.amzn2.0.8.i686

src:
    ImageMagick-6.9.10.97-1.amzn2.0.8.src

x86_64:
    ImageMagick-6.9.10.97-1.amzn2.0.8.x86_64
    ImageMagick-devel-6.9.10.97-1.amzn2.0.8.x86_64
    ImageMagick-doc-6.9.10.97-1.amzn2.0.8.x86_64
    ImageMagick-perl-6.9.10.97-1.amzn2.0.8.x86_64
    ImageMagick-c++-6.9.10.97-1.amzn2.0.8.x86_64
    ImageMagick-c++-devel-6.9.10.97-1.amzn2.0.8.x86_64
    ImageMagick-debuginfo-6.9.10.97-1.amzn2.0.8.x86_64