TIFFGetProfiles() in /coders/tiff.c calls strstr() which causes a large out-of-bounds read when it searches for `"dc:format=\"image/dng\"` within `profile` due to improper string handling, when a crafted input file is provided to ImageMagick. The patch uses a StringInfo type instead of a raw C string to remedy this. This could cause an impact to availability of the application. This flaw affects ImageMagick versions prior to 7.0.9-0.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Huawei Euleros 2_0_sp3 | huawei-euleros-2_0_sp3-upgrade-imagemagickhuawei-euleros-2_0_sp3-upgrade-imagemagick-c++huawei-euleros-2_0_sp3-upgrade-imagemagick-libshuawei-euleros-2_0_sp3-upgrade-imagemagick-perl | May 25, 2022 | Dec 8, 2020 | |
| Huawei Euleros 2_0_sp5 | huawei-euleros-2_0_sp5-upgrade-imagemagickhuawei-euleros-2_0_sp5-upgrade-imagemagick-c++huawei-euleros-2_0_sp5-upgrade-imagemagick-libshuawei-euleros-2_0_sp5-upgrade-imagemagick-perl | Apr 26, 2022 | Dec 8, 2020 | |
| Huawei Euleros 2_0_sp8 | huawei-euleros-2_0_sp8-upgrade-imagemagickhuawei-euleros-2_0_sp8-upgrade-imagemagick-c++huawei-euleros-2_0_sp8-upgrade-imagemagick-libshuawei-euleros-2_0_sp8-upgrade-imagemagick-perl | Apr 26, 2022 | Dec 8, 2020 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Dec 8, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub