Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-44267

Опубликовано: 06 фев. 2023
Источник: redhat
CVSS3: 7.5
EPSS Средний

Описание

ImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parses a PNG image (e.g., for resize), the convert process could be left waiting for stdin input.

A vulnerability was found in ImageMagick that is triggered when the software parses a PNG image containing a single dash (-) in the filename. To remotely exploit this bug, an attacker can upload a malicious PNG with a text chunk that adds a single dash in the name to any site using ImageMagick. The site would then parse the image, and ImageMagick would interpret the text string as the filename, loading the content as a raw profile. If this text string contains a single dash, the program would then try to read content from the standard input, potentially leaving the conversion process waiting infinitely, causing a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2167593ImageMagick: Denial of Service when it parses a PNG image

EPSS

Процентиль: 94%
0.1601
Средний

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 2 лет назад

ImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parses a PNG image (e.g., for resize), the convert process could be left waiting for stdin input.

CVSS3: 6.5
nvd
больше 2 лет назад

ImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parses a PNG image (e.g., for resize), the convert process could be left waiting for stdin input.

CVSS3: 6.5
debian
больше 2 лет назад

ImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parse ...

CVSS3: 6.5
github
больше 2 лет назад

ImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parses a PNG image (e.g., for resize), the convert process could be left waiting for stdin input.

CVSS3: 4.3
fstec
больше 2 лет назад

Уязвимость графического редактора ImageMagick, связанная с ошибками управления ресурсом, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 94%
0.1601
Средний

7.5 High

CVSS3