We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-3428

Imagemagick: heap-buffer-overflow in coders/tiff.c



Description

A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local attacker to trick the user into opening a specially crafted file, resulting in an application crash and denial of service.

Reserved 2023-06-27 | Published 2023-10-04 | Updated 2025-02-07 | Assigner redhat


MEDIUM: 6.2CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

Heap-based Buffer Overflow

Product status

Default status
unknown

Default status
unknown

Timeline

2023-06-27:Reported to Red Hat.
2023-06-27:Made public.

Credits

Red Hat would like to thank Hardik shah of Vehere (Dawn Treaders team) for reporting this issue.

References

access.redhat.com/security/cve/CVE-2023-3428 vdb-entry

bugzilla.redhat.com/show_bug.cgi?id=2218369 (RHBZ#2218369) issue-tracking

cve.org (CVE-2023-3428)

nvd.nist.gov (CVE-2023-3428)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2023-3428

Support options

Helpdesk Chat, Email, Knowledgebase