Denial of Service Vulnerability in ImageMagick by ImageMagick Studio LLC
CVE-2022-44267
6.5MEDIUM
What is CVE-2022-44267?
ImageMagick 7.1.0-49 contains a vulnerability that can lead to Denial of Service when handling PNG images. Specifically, the issue arises during the parsing process, where the convert command may become unresponsive while waiting for standard input, potentially causing disruptions in service availability. Users of this version should take immediate action to update their installations to mitigate these risks and ensure stable operation.
References
EPSS Score
16% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved