5.5
CVSSv3

CVE-2023-34475

Published: 16/06/2023 Updated: 07/11/2023
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

A heap use after free issue exists in ImageMagick's ReplaceXmpValue() function in MagickCore/profile.c. An attacker could trick user to open a specially crafted file to convert, triggering an heap-use-after-free write error, allowing an application to crash, resulting in a denial of service.

Vulnerable Product Search on Vulmon Subscribe to Product

imagemagick imagemagick

fedoraproject extra packages for enterprise linux 8.0

fedoraproject fedora 37

fedoraproject fedora 38

Vendor Advisories

Description<!----> This CVE is under investigation by Red Hat Product Security ...