ALAS-2023-1831

Related Vulnerabilities: CVE-2022-48541  

A memory leak in ImageMagick 7.0.10-45 and 6.9.11-22 allows remote attackers to perform a denial of service via the "identify -help" command. (CVE-2022-48541)

ALAS-2023-1831


Amazon Linux AMI Security Advisory: ALAS-2023-1831
Advisory Release Date: 2023-09-13 23:15 Pacific
Advisory Updated Date: 2023-09-25 20:12 Pacific
Severity: Medium

Issue Overview:

A memory leak in ImageMagick 7.0.10-45 and 6.9.11-22 allows remote attackers to perform a denial of service via the "identify -help" command. (CVE-2022-48541)


Affected Packages:

ImageMagick


Issue Correction:
Run yum update ImageMagick to update your system.

New Packages:
i686:
    ImageMagick-devel-6.9.10.97-1.28.amzn1.i686
    ImageMagick-debuginfo-6.9.10.97-1.28.amzn1.i686
    ImageMagick-6.9.10.97-1.28.amzn1.i686
    ImageMagick-perl-6.9.10.97-1.28.amzn1.i686
    ImageMagick-c++-6.9.10.97-1.28.amzn1.i686
    ImageMagick-doc-6.9.10.97-1.28.amzn1.i686
    ImageMagick-c++-devel-6.9.10.97-1.28.amzn1.i686

src:
    ImageMagick-6.9.10.97-1.28.amzn1.src

x86_64:
    ImageMagick-perl-6.9.10.97-1.28.amzn1.x86_64
    ImageMagick-debuginfo-6.9.10.97-1.28.amzn1.x86_64
    ImageMagick-6.9.10.97-1.28.amzn1.x86_64
    ImageMagick-c++-devel-6.9.10.97-1.28.amzn1.x86_64
    ImageMagick-c++-6.9.10.97-1.28.amzn1.x86_64
    ImageMagick-doc-6.9.10.97-1.28.amzn1.x86_64
    ImageMagick-devel-6.9.10.97-1.28.amzn1.x86_64