Lucene search

K
cveRedhatCVE-2022-1115
HistoryAug 29, 2022 - 3:15 p.m.

CVE-2022-1115

2022-08-2915:15:10
CWE-119
CWE-787
redhat
web.nvd.nist.gov
59
4
cve-2022-1115
imagemagick
heap buffer overflow
tiff
denial of service
vulnerability

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

44.8%

A heap-buffer-overflow flaw was found in ImageMagick’s PushShortPixel() function of quantum-private.h file. This vulnerability is triggered when an attacker passes a specially crafted TIFF image file to ImageMagick for conversion, potentially leading to a denial of service.

Affected configurations

Nvd
Vulners
Node
imagemagickimagemagickRange<6.9.12-44
OR
imagemagickimagemagickRange7.0.0-07.1.0-29
VendorProductVersionCPE
imagemagickimagemagick*cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "ImageMagick",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Fixed in ImageMagick6 v6.9.12-44, ImageMagick7 v7.1.0-29"
      }
    ]
  }
]

Social References

More

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

44.8%