5.5
CVSSv3

CVE-2023-1906

Published: 12/04/2023 Updated: 07/11/2023
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

A heap-based buffer overflow issue exists in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

imagemagick imagemagick 7.1.1-4

imagemagick imagemagick

fedoraproject extra packages for enterprise linux 8.0

fedoraproject fedora 37

Vendor Advisories

Debian Bug report logs - #1034373 imagemagick: CVE-2023-1906 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Thu, 13 Apr 2023 18:45:02 UTC Severity: important Tags: security, up ...