Vulnerability Description
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Imagemagick | Imagemagick | <= 6.7.5-7 |
| Debian | Debian Linux | 6.0 |
| Canonical | Ubuntu Linux | 10.04 |
| Redhat | Storage | 2.0 |
| Redhat | Enterprise Linux Desktop | 5.0 |
| Redhat | Enterprise Linux Eus | 6.2 |
| Redhat | Enterprise Linux Server | 5.0 |
| Redhat | Enterprise Linux Server Aus | 6.2 |
| Redhat | Enterprise Linux Server Eus | 6.2 |
| Redhat | Enterprise Linux Workstation | 5.0 |
Related Weaknesses (CWE)
References
- http://rhn.redhat.com/errata/RHSA-2012-0544.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-0545.htmlThird Party Advisory
- http://secunia.com/advisories/47926Broken Link
- http://secunia.com/advisories/48247Broken Link
- http://secunia.com/advisories/48259Broken Link
- http://secunia.com/advisories/49043Broken Link
- http://secunia.com/advisories/49063Broken Link
- http://secunia.com/advisories/49068Broken Link
- http://ubuntu.com/usn/usn-1435-1Third Party Advisory
- http://www.cert.fi/en/reports/2012/vulnerability595210.htmlBroken Link
- http://www.debian.org/security/2012/dsa-2427Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-201203-09.xmlThird Party Advisory
- http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=20286Issue TrackingPatchVendor Advisory
- http://www.osvdb.org/79003Broken Link
- http://www.securityfocus.com/bid/51957Third Party AdvisoryVDB Entry
FAQ
What is CVE-2012-0248?
CVE-2012-0248 is a vulnerability with a CVSS score of 5.5 (MEDIUM). ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the ID...
How severe is CVE-2012-0248?
CVE-2012-0248 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-0248?
Check the references section above for vendor advisories and patch information. Affected products include: Imagemagick Imagemagick, Debian Debian Linux, Canonical Ubuntu Linux, Redhat Storage, Redhat Enterprise Linux Desktop.