Bug 2167593 (CVE-2022-44267) - CVE-2022-44267 ImageMagick: Denial of Service when it parses a PNG image
Summary: CVE-2022-44267 ImageMagick: Denial of Service when it parses a PNG image
Keywords:
Status: NEW
Alias: CVE-2022-44267
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2167595 2167596 2167597
Blocks: 2167598
TreeView+ depends on / blocked
 
Reported: 2023-02-07 05:03 UTC by Sandipan Roy
Modified: 2023-07-07 08:35 UTC (History)
6 users (show)

Fixed In Version: ImaeMagick 7.1.0-52, ImageMagick 6.9.12-67
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Sandipan Roy 2023-02-07 05:03:55 UTC
ImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parses a PNG image (e.g., for resize), the convert process could be left waiting for stdin input.

https://imagemagick.org/
https://www.metabaseq.com/imagemagick-zero-days/

Comment 1 Sandipan Roy 2023-02-07 05:06:18 UTC
Created ImageMagick tracking bugs for this issue:

Affects: epel-8 [bug 2167595]
Affects: fedora-36 [bug 2167596]
Affects: fedora-37 [bug 2167597]


Note You need to log in before you can comment on or make changes to this bug.