Heap Use After Free Vulnerability in ImageMagick Software
CVE-2023-34475
5.5MEDIUM
What is CVE-2023-34475?
A critical vulnerability has been identified in ImageMagick's ReplaceXmpValue() function within MagickCore/profile.c, marked by a heap use after free issue. An attacker can exploit this flaw by persuading users to open a specially constructed file for conversion. This action can lead to a heap-use-after-free write error, causing applications to crash and resulting in potential denial of service. It is essential for users and administrators to update their ImageMagick installations to safeguard against this risk.
Affected Version(s)
ImageMagick 7.1.1-10