A heap use after free issue exists in ImageMagick's ReplaceXmpValue() function in MagickCore/profile.c. An attacker could trick user to open a specially crafted file to convert, triggering an heap-use-after-free write error, allowing an application to crash, resulting in a denial of service.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
imagemagick imagemagick |
||
fedoraproject extra packages for enterprise linux 8.0 |
||
fedoraproject fedora 37 |
||
fedoraproject fedora 38 |