QID 357342

Date Published: 2024-03-20

QID 357342: Amazon Linux Security Advisory for ImageMagick : ALAS-2024-1926

integer overflow in magickcore/profile.c in imagemagick before 7.0.2-1 allows remote attackers to cause a denial of service (segmentation fault) or possibly execute arbitrary code via vectors involving the offset variable. (
( CVE-2016-5841) imagemagick 7.0.7-12 q16, a cpu exhaustion vulnerability was found in the function readddsinfo in coders/dds.c, which allows attackers to cause a denial of service. (
( CVE-2017-1000476) the readxwdimage function in coders\xwd.c in imagemagick 7.0.5-6 has a memory leak vulnerability that can cause memory exhaustion via a crafted length (number of color-map entries) field in the header of an xwd file. (
( CVE-2017-11166) in imagemagick 7.0.6-6, a memory exhaustion vulnerability was found in the function readtiffimage, which allows attackers to cause a denial of service. (
( CVE-2017-12805) in imagemagick 7.0.6-6, a memory exhaustion vulnerability was found in the function format8bim, which allows attackers to cause a denial of service. (
( CVE-2017-12806) in imagemagick before 6.9.9-0 and 7.x before 7.0.6-1, the readonemngimage function in coders/png.c has an out-of-bounds read with the mng clip chunk. (
( CVE-2017-13139) a memory leak vulnerability has been discovered in imagemagick in the readpcdimage function of coders/pcd.c file.
An attacker could use this flaw to cause a denial of service via a crafted file. (

Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Please refer to Amazon advisory: ALAS-2024-1926 for affected packages and patching details, or update with your package manager.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ALAS-2024-1926 amazon linux URL Logo alas.aws.amazon.com/ALAS-2024-1926.html