LWN.net Logo

ImageMagick: integer overflow

Package(s):ImageMagick CVE #(s):CVE-2012-1620
Created:June 22, 2012 Updated:June 27, 2012
Description:

From the Red Hat Bugzilla entry:

An out-of heap-based buffer read flaw was found in the way ImageMagick, an image display and manipulation tool for the X Window System, retrieved Exchangeable image file format (Exif) header tag information from certain JPEG files. A remote attacker could provide a JPEG image file, with EXIF header containing specially-crafted tag values, which once opened in some ImageMagick tool would lead to the crash of that tool (denial of service).

Alerts:
Fedora FEDORA-2012-9313 2012-06-22

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds