๐Ÿ” CVE Alert

CVE-2023-34475

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A heap use after free issue was discovered in ImageMagick's ReplaceXmpValue() function in MagickCore/profile.c. An attacker could trick user to open a specially crafted file to convert, triggering an heap-use-after-free write error, allowing an application to crash, resulting in a denial of service.

CWE CWE-416
Vendor n/a
Product imagemagick
Published Jun 16, 2023
Last Updated Dec 3, 2024
Stay Ahead of the Next One

Get instant alerts for n/a imagemagick

Be the first to know when new unknown vulnerabilities affecting n/a imagemagick are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

n/a / ImageMagick
7.1.1-10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/ImageMagick/ImageMagick/commit/1061db7f80fdc9ef572ac60b55f408f7bab6e1b0 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2214149 access.redhat.com: https://access.redhat.com/security/cve/CVE-2023-34475 lists.fedoraproject.org: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/45DUUXYMAEEAW55GSLAXN25VPKCRAIDA/ lists.fedoraproject.org: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UFQJCYJ23HWHNDOVKBHZQ7HCXXL6MM3/