The TIFFSetProfiles function in coders/tiff.c in ImageMagick 7.0.6 has incorrect expectations about whether LibTIFF TIFFGetField return values imply that data validation has occurred, which allows remote attackers to cause a denial of service (use-after-free after an invalid call to TIFFSetField, and application crash) via a crafted file.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade imagemagick | Jan 14, 2021 | Sep 18, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 23, 2017 |
| Ubuntu | — | Upgrade libmagickcore-6.q16-3Upgrade imagemagick-6.q16Upgrade libmagickcore-6.q16-6Upgrade libmagick++-6.q16-7Upgrade libmagickcore-6.q16-6-extraUpgrade imagemagickUpgrade libmagick++-6.q16-8Upgrade libmagickcore-6.q16-3-extra | Jun 16, 2021 | Sep 17, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub