Heap-based buffer overflow in ImageMagick - CVE-2023-3745
Published: August 4, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error within the PushCharPixel() function in quantum-private.h. A remote attacker can pass specially crafted data to the application, trigger a heap-based buffer overflow and perform a denial of service (DoS) attack.
Affected software
Amazon Linux AMI
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE CaaS Platform
SUSE Linux Enterprise Workstation Extension 12
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
openSUSE Leap
ImageMagick-config-6-SUSE
ImageMagick-debugsource
ImageMagick
libMagick++-6_Q16-3-debuginfo
ImageMagick-debuginfo
libMagickCore-6_Q16-1-32bit
libMagick++-6_Q16-3
libMagickCore-6_Q16-1-debuginfo-32bit
perl-PerlMagick
ImageMagick-devel
libMagick++-devel
ImageMagick-config-6-upstream
perl-PerlMagick-debuginfo
libMagickCore-6_Q16-1
libMagickCore-6_Q16-1-debuginfo
libMagickWand-6_Q16-1
libMagickWand-6_Q16-1-debuginfo
ImageMagick-config-7-SUSE
libMagickWand-7_Q16HDRI6
libMagick++-7_Q16HDRI4
libMagickCore-7_Q16HDRI6-debuginfo
ImageMagick-config-7-upstream
libMagick++-7_Q16HDRI4-debuginfo
libMagickCore-7_Q16HDRI6
libMagickWand-7_Q16HDRI6-debuginfo
libMagickCore-7_Q16HDRI6-32bit-debuginfo
libMagickWand-7_Q16HDRI6-32bit
libMagick++-7_Q16HDRI4-32bit
libMagickWand-7_Q16HDRI6-32bit-debuginfo
libMagickCore-7_Q16HDRI6-32bit
libMagick++-7_Q16HDRI4-32bit-debuginfo
How to mitigate CVE-2023-3745
ImageMagick-config-6-SUSE - update to 6.8.8.1-71.195.1
ImageMagick-debugsource - addressed in versions 6.8.8.1-71.195.1, 7.0.7.34-150000.3.123.1
ImageMagick - addressed in versions 6.8.8.1-71.195.1, 7.0.7.34-150000.3.123.1
libMagick++-6_Q16-3-debuginfo - update to 6.8.8.1-71.195.1
ImageMagick-debuginfo - addressed in versions 6.8.8.1-71.195.1, 7.0.7.34-150000.3.123.1
libMagickCore-6_Q16-1-32bit - update to 6.8.8.1-71.195.1
libMagick++-6_Q16-3 - update to 6.8.8.1-71.195.1
libMagickCore-6_Q16-1-debuginfo-32bit - update to 6.8.8.1-71.195.1
perl-PerlMagick - addressed in versions 6.8.8.1-71.195.1, 7.0.7.34-150000.3.123.1
ImageMagick-devel - addressed in versions 6.8.8.1-71.195.1, 7.0.7.34-150000.3.123.1
libMagick++-devel - addressed in versions 6.8.8.1-71.195.1, 7.0.7.34-150000.3.123.1
ImageMagick-config-6-upstream - update to 6.8.8.1-71.195.1
perl-PerlMagick-debuginfo - addressed in versions 6.8.8.1-71.195.1, 7.0.7.34-150000.3.123.1
libMagickCore-6_Q16-1 - update to 6.8.8.1-71.195.1
libMagickCore-6_Q16-1-debuginfo - update to 6.8.8.1-71.195.1
libMagickWand-6_Q16-1 - update to 6.8.8.1-71.195.1
libMagickWand-6_Q16-1-debuginfo - update to 6.8.8.1-71.195.1
ImageMagick - update to 6.9.10.97-1.27
ImageMagick-config-7-SUSE - update to 7.0.7.34-150000.3.123.1
libMagickWand-7_Q16HDRI6 - addressed in versions 7.0.7.34-150000.3.123.1, 7.0.7.34-150200.10.51.1
libMagick++-7_Q16HDRI4 - addressed in versions 7.0.7.34-150000.3.123.1, 7.0.7.34-150200.10.51.1
libMagickCore-7_Q16HDRI6-debuginfo - addressed in versions 7.0.7.34-150000.3.123.1, 7.0.7.34-150200.10.51.1
ImageMagick-config-7-upstream - update to 7.0.7.34-150000.3.123.1
libMagick++-7_Q16HDRI4-debuginfo - addressed in versions 7.0.7.34-150000.3.123.1, 7.0.7.34-150200.10.51.1
libMagickCore-7_Q16HDRI6 - addressed in versions 7.0.7.34-150000.3.123.1, 7.0.7.34-150200.10.51.1
libMagickWand-7_Q16HDRI6-debuginfo - addressed in versions 7.0.7.34-150000.3.123.1, 7.0.7.34-150200.10.51.1
libMagickCore-7_Q16HDRI6-32bit-debuginfo - update to 7.0.7.34-150200.10.51.1
libMagickWand-7_Q16HDRI6-32bit - update to 7.0.7.34-150200.10.51.1
libMagick++-7_Q16HDRI4-32bit - update to 7.0.7.34-150200.10.51.1
libMagickWand-7_Q16HDRI6-32bit-debuginfo - update to 7.0.7.34-150200.10.51.1
libMagickCore-7_Q16HDRI6-32bit - update to 7.0.7.34-150200.10.51.1
libMagick++-7_Q16HDRI4-32bit-debuginfo - update to 7.0.7.34-150200.10.51.1
External References
- https://github.com/ImageMagick/ImageMagick6/commit/b466a96965afc1308a4ace93f5535c2b770f294b
- https://github.com/ImageMagick/ImageMagick/commit/54cdc146bbe50018526770be201b56643ad58ba7
- https://github.com/ImageMagick/ImageMagick/commit/651672f19c75161a6159d9b6838fd3095b6c5304
- https://bugzilla.redhat.com/show_bug.cgi?id=2223557
- https://github.com/ImageMagick/ImageMagick/issues/1857
- https://github.com/ImageMagick/ImageMagick6/commit/7486477aa00c5c7856b111506da075b6cdfa8b73
- https://access.redhat.com/security/cve/CVE-2023-3745