4.3
CVSSv2

CVE-2012-3437

Published: 07/08/2012 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The Magick_png_malloc function in coders/png.c in ImageMagick 6.7.8 and previous versions does not use the proper variable type for the allocation size, which might allow remote malicious users to cause a denial of service (crash) via a crafted PNG file that triggers incorrect memory allocation.

Vulnerable Product Search on Vulmon Subscribe to Product

imagemagick imagemagick 6.7.8-6

Vendor Advisories

ImageMagick could be made to crash or run programs as your login if it opened a specially crafted file ...
Debian Bug report logs - #683285 CVE-2012-3437 Package: imagemagick; Maintainer for imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Source for imagemagick is src:imagemagick (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Mon, 30 Jul 201 ...