CVE-2023-1289
Summary
| CVE | CVE-2023-1289 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-23 20:15:00 UTC |
| Updated | 2023-03-30 15:07:00 UTC |
| Description | A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a remote attacker to pass a specially crafted SVG file that leads to a segmentation fault, generating many trash files in "/tmp," resulting in a denial of service. When ImageMagick crashes, it generates a lot of trash files. These trash files can be large if the SVG file contains many render actions. In a denial of service attack, if a remote attacker uploads an SVG file of size t, ImageMagick generates files of size 103*t. If an attacker uploads a 100M SVG, the server will generate about 10G. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 2176858 – (CVE-2023-1289) CVE-2023-1289 ImageMagick: Specially crafted SVG leads to segmentation fault and generate trash files in "/tmp", possible to leverage DoS |
MISC |
bugzilla.redhat.com |
|
| erecursion detection · ImageMagick/ImageMagick@c5b23cb · GitHub |
MISC |
github.com |
|
| Specially crafted SVG leads to segmentation fault and generate trash files in "/tmp", possible to leverage DoS · Advisory · ImageMagick/ImageMagick · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 199524 Ubuntu Security Notification for ImageMagick Vulnerabilities (USN-6200-1)
- 354892 Amazon Linux Security Advisory for ImageMagick : ALAS2-2023-2014
- 355102 Amazon Linux Security Advisory for ImageMagick : ALAS-2023-1745
- 355205 Amazon Linux Security Advisory for ImageMagick : ALAS2023-2023-150
- 6000485 Debian Security Update for imagemagick (DLA 3737-1)
- 6000487 Debian Security Update for imagemagick (DSA 5628-1)
- 753860 SUSE Enterprise Linux Security Update for ImageMagick (SUSE-SU-2023:1734-1)
- 753886 SUSE Enterprise Linux Security Update for ImageMagick (SUSE-SU-2023:1756-1)