CVE-2022-2719
Published on: Not Yet Published
Last Modified on: 08/16/2022 04:00:00 PM UTC
Certain versions of Extra Packages For Enterprise Linux from Fedoraproject contain the following vulnerability:
In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was made in MagickWand/operation.c, due to a NULL image list. This could potentially cause a denial of service. This was fixed in upstream ImageMagick version 7.1.0-30.
- CVE-2022-2719 has been assigned by
seca[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 5.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
2116537 – (CVE-2022-2719) CVE-2022-2719 ImageMagick: Assertion Failure could lead to DoS due to attempted writing of NULL image list | bugzilla.redhat.com text/html |
![]() |
Related QID Numbers
- 283136 Fedora Security Update for ImageMagick (FEDORA-2022-0a0e4cb94a)
- 354413 Amazon Linux Security Advisory for ImageMagick : ALAS2022-2022-215
- 354586 Amazon Linux Security Advisory for ImageMagick : ALAS-2022-215
- 502537 Alpine Linux Security Update for imagemagick
- 502870 Alpine Linux Security Update for imagemagick
- 753205 SUSE Enterprise Linux Security Update for ImageMagick (SUSE-SU-2022:3119-1)
- 753269 SUSE Enterprise Linux Security Update for ImageMagick (SUSE-SU-2022:2998-1)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Fedoraproject | Extra Packages For Enterprise Linux | 8.0 | All | All | All |
Operating System | Fedoraproject | Fedora | 36 | All | All | All |
Application | Imagemagick | Imagemagick | All | All | All | All |
- cpe:2.3:a:fedoraproject:extra_packages_for_enterprise_linux:8.0:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*:
- cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-2719 : In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was ma… twitter.com/i/web/status/1… | 2022-08-10 20:39:53 |
![]() |
Imagemagick - CVE-2022-2719: bugzilla.redhat.com/show_bug.cgi?i… | 2022-08-10 23:00:06 |
![]() |
CVE-2022-2719 | 2022-08-10 21:38:22 |