Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-1289
HistoryMar 23, 2023 - 12:00 a.m.

CVE-2023-1289

2023-03-2300:00:00
ubuntu.com
ubuntu.com
23
imagemagick
svg file
denial of service
segmentation fault
trash files
remote attacker
ubuntu
6.9.x
patchs

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

41.6%

A vulnerability was discovered in ImageMagick where a specially created SVG
file loads itself and causes a segmentation fault. This flaw allows a
remote attacker to pass a specially crafted SVG file that leads to a
segmentation fault, generating many trash files in “/tmp,” resulting in a
denial of service. When ImageMagick crashes, it generates a lot of trash
files. These trash files can be large if the SVG file contains many render
actions. In a denial of service attack, if a remote attacker uploads an SVG
file of size t, ImageMagick generates files of size 103*t. If an attacker
uploads a 100M SVG, the server will generate about 10G.

Notes

Author Note
rodrigo-zaiden vulnerability was added at some point in 6.9.x. It does not reproduce in older versions. In Ubuntu it affects bionic and later. additional patchs may be needed, some data structures are not available in ImageMagick6, and there is no commit from upstream in ImageMagick6.
OSVersionArchitecturePackageVersionFilename
ubuntu20.04noarchimagemagick< 8:6.9.10.23+dfsg-2.1ubuntu11.10UNKNOWN
ubuntu22.04noarchimagemagick< 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5UNKNOWN
ubuntu22.10noarchimagemagick< 8:6.9.11.60+dfsg-1.3ubuntu0.22.10.5UNKNOWN
ubuntu23.04noarchimagemagick< 8:6.9.11.60+dfsg-1.6ubuntu0.23.04.1UNKNOWN
ubuntu23.10noarchimagemagick< 8:6.9.11.60+dfsg-1.6ubuntu1UNKNOWN
ubuntu24.04noarchimagemagick< 8:6.9.11.60+dfsg-1.6ubuntu1UNKNOWN

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

41.6%