5.5
CVSSv3

CVE-2023-3195

Published: 16/06/2023 Updated: 07/11/2023
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

A stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. This flaw allows an malicious user to trick the user into opening a specially crafted malicious tiff file, causing an application to crash, resulting in a denial of service.

Vulnerable Product Search on Vulmon Subscribe to Product

imagemagick imagemagick

fedoraproject extra packages for enterprise linux 8.0

fedoraproject fedora 37

fedoraproject fedora 38

Vendor Advisories

stack overflow when parsing malicious tiff image (CVE-2023-3195) ...
stack overflow when parsing malicious tiff image (CVE-2023-3195) The upstream bug report describes this issue as follows:"A vulnerability was found in ImageMagick <=711, where heap-based buffer overflow was found in coders/tiffc" (CVE-2023-3428) ...
Description<!----> This CVE is under investigation by Red Hat Product Security ...