CVE-2023-3428
Summary
| CVE | CVE-2023-3428 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-04 19:15:00 UTC |
| Updated | 2023-11-07 04:18:00 UTC |
| Description | A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local attacker to trick the user into opening a specially crafted file, resulting in an application crash and denial of service. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 199524 Ubuntu Security Notification for ImageMagick Vulnerabilities (USN-6200-1)
- 296105 Oracle Solaris 11.4 Support Repository Update (SRU) 63.157.1 Missing (CPUOCT2023)
- 355569 Amazon Linux Security Advisory for ImageMagick : ALAS-2023-1781
- 355595 Amazon Linux Security Advisory for ImageMagick : ALAS2-2023-2123
- 355646 Amazon Linux Security Advisory for ImageMagick : ALAS2023-2023-249
- 6000487 Debian Security Update for imagemagick (DSA 5628-1)