ImageMagick
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*
- < 7.1.2-15
- < 6.9.13-40
A denial-of-service vulnerability has been identified in ImageMagick versions prior to 7.1.2-15 and 6.9.13-40. The issue arises when a crafted profile containing invalid IPTC data is processed with 'IPTCTEXT', leading to an infinite loop. This vulnerability requires no privileges or user interaction to exploit.
Exploitation of this vulnerability causes an infinite loop, which can lead to a denial-of-service condition by consuming system resources and potentially causing the application to become unresponsive.
Users can upgrade to ImageMagick versions 7.1.2-15 or 6.9.13-40 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.