QID 355205
Date Published: 2023-05-29
QID 355205: Amazon Linux Security Advisory for ImageMagick : ALAS2023-2023-150
A vulnerability was discovered in imagemagick where a specially created svg file loads itself and causes a segmentation fault.
This flaw allows a remote attacker to pass a specially crafted svg file that leads to a segmentation fault, generating many trash files in "/tmp," resulting in a denial of service.
When imagemagick crashes, it generates a lot of trash files.
These trash files can be large if the svg file contains many render actions.
In a denial of service attack, if a remote attacker uploads an svg file of size t, imagemagick generates files of size 103*t.
If an attacker uploads a 100m svg, the server will generate about 10g. (cve-2023-1289)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.
- ALAS2023-2023-150 -
alas.aws.amazon.com/AL2023/ALAS-2023-150.html
CVEs related to QID 355205
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS2023-2023-150 | amazon linux 2023 |
|