CVE-2023-3745

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
24/07/2023
Last modified:
07/11/2023

Description

A heap-based buffer overflow issue was found in ImageMagick's PushCharPixel() function in quantum-private.h. This issue may allow a local attacker to trick the user into opening a specially crafted file, triggering an out-of-bounds read error and allowing an application to crash, resulting in a denial of service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* 6.0 (including) 6.9-11-0 (excluding)
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* 7.0.0-0 (including) 7.0.10-0 (excluding)