Denial of Service Vulnerability in ImageMagick by ImageMagick Studio LLC
CVE-2022-44267

6.5MEDIUM

Key Information:

Vendor
CVE Published:
6 February 2023

What is CVE-2022-44267?

ImageMagick 7.1.0-49 contains a vulnerability that can lead to Denial of Service when handling PNG images. Specifically, the issue arises during the parsing process, where the convert command may become unresponsive while waiting for standard input, potentially causing disruptions in service availability. Users of this version should take immediate action to update their installations to mitigate these risks and ensure stable operation.

References

EPSS Score

16% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.