Vulnerability Description
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset and count values in the ResolutionUnit tag in the EXIF IFD0 of an image.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Imagemagick | Imagemagick | <= 6.7.5-7 |
| Debian | Debian Linux | 6.0 |
| Canonical | Ubuntu Linux | 10.04 |
| Redhat | Storage | 2.0 |
| Redhat | Enterprise Linux Desktop | 5.0 |
| Redhat | Enterprise Linux Eus | 6.2 |
| Redhat | Enterprise Linux Server | 5.0 |
| Redhat | Enterprise Linux Server Aus | 6.2 |
| Redhat | Enterprise Linux Server Eus | 6.2 |
| Redhat | Enterprise Linux Workstation | 5.0 |
Related Weaknesses (CWE)
References
- http://rhn.redhat.com/errata/RHSA-2012-0544.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-0545.htmlThird Party Advisory
- http://secunia.com/advisories/47926Broken Link
- http://secunia.com/advisories/48247Broken Link
- http://secunia.com/advisories/48259Broken Link
- http://secunia.com/advisories/49043Broken Link
- http://secunia.com/advisories/49063Broken Link
- http://secunia.com/advisories/49068Broken Link
- http://ubuntu.com/usn/usn-1435-1Third Party Advisory
- http://www.cert.fi/en/reports/2012/vulnerability595210.htmlBroken Link
- http://www.debian.org/security/2012/dsa-2427Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-201203-09.xmlThird Party Advisory
- http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=20286Issue TrackingPatchVendor Advisory
- http://www.osvdb.org/79003Broken Link
- http://www.securitytracker.com/id?1027032Third Party AdvisoryVDB Entry
FAQ
What is CVE-2012-0247?
CVE-2012-0247 is a vulnerability with a CVSS score of 8.8 (HIGH). ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset and count values in the ResolutionUnit t...
How severe is CVE-2012-0247?
CVE-2012-0247 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-0247?
Check the references section above for vendor advisories and patch information. Affected products include: Imagemagick Imagemagick, Debian Debian Linux, Canonical Ubuntu Linux, Redhat Storage, Redhat Enterprise Linux Desktop.