Heap-Based Buffer Overflow in ImageMagick Package by Red Hat
CVE-2023-2157

5.5MEDIUM

Key Information:

Vendor
CVE Published:
6 June 2023

What is CVE-2023-2157?

A heap-based buffer overflow vulnerability has been identified in the ImageMagick package, which potentially allows an attacker to manipulate memory allocations. This can lead to unexpected application behavior, including crashes. It is crucial for users of ImageMagick to apply the latest updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

ImageMagick ImageMagick 7.1.1-9

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.