5.5
CVSSv3

CVE-2023-3428

Published: 04/10/2023 Updated: 07/11/2023
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local malicious user to trick the user into opening a specially crafted file, resulting in an application crash and denial of service.

Vulnerable Product Search on Vulmon Subscribe to Product

imagemagick imagemagick

fedoraproject fedora -

fedoraproject extra packages for enterprise linux 8.0

Vendor Advisories

The upstream bug report describes this issue as follows:"A vulnerability was found in ImageMagick <=711, where heap-based buffer overflow was found in coders/tiffc" (CVE-2023-3428) ...
stack overflow when parsing malicious tiff image (CVE-2023-3195) The upstream bug report describes this issue as follows:"A vulnerability was found in ImageMagick <=711, where heap-based buffer overflow was found in coders/tiffc" (CVE-2023-3428) ...
Description<!----> This CVE is under investigation by Red Hat Product Security ...