A heap-based buffer overflow issue exists in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
imagemagick imagemagick 7.1.1-4 |
||
imagemagick imagemagick |
||
fedoraproject extra packages for enterprise linux 8.0 |
||
fedoraproject fedora 37 |