ImageMagick
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*
- <= 7.1.1-13
A heap buffer overflow vulnerability has been identified in ImageMagick versions through 7.1.1-13. When processing a specially crafted TIFF file, ImageMagick crashes, creating a denial-of-service condition. This vulnerability has been patched in version 7.1.1-14.
Exploitation of this vulnerability leads to a crash of the ImageMagick application, causing a denial-of-service condition.
The vulnerability can be reproduced by using the 'magick' command-line tool to process a crafted TIFF file. The command should direct the output to '/dev/null'.
Users can upgrade to ImageMagick version 7.1.1-14 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.