MEDIUM
ImageMagick: Undefined behaviors of casting double to size_t in svg, mvg and other coders
Published May 30, 2023
5.5
MEDIUMCVSS 3.1
EPSS 0.95%
Description
A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other coders (recurring bugs of CVE-2022-32546).
Affected products
- Vendor n/a Product ImageMagick Defaultn/a
- Version ImageMagick-6.7StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | ImageMagick | n/a |
|
Configuration 1
- < 7.1.1-11
Configuration 2
OR
- 8.0
- 37
- 38
Configuration 3
OR
- 6.0
- 7.0
Configuration 4
- 10.0
No data.
Red Hat Enterprise Linux 6
ImageMagick
Out of support scope
Red Hat Enterprise Linux 7
ImageMagick
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | ImageMagick | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | ImageMagick | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- https://access.redhat.com/security/cve/CVE-2023-34151 Third Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2210657 Issue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-38251 Advisory
- https://github.com/ImageMagick/ImageMagick/issues/6341 ExploitIssue TrackingPatch
- https://lists.debian.org/debian-lts-announce/2024/02/msg00007.html mailing-listMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UFQJCYJ23HWHNDOVKBHZQ7HCXXL6MM3/ vendor-advisoryMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2ZUHZXQ2C3JZYKPW4XHCMVVL467MA2V/ vendor-advisoryMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-34151
- https://www.cve.org/CVERecord?id=CVE-2023-34151
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-34151 | Third Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2210657 | Issue TrackingThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-38251 | Advisory | |
| https://github.com/ImageMagick/ImageMagick/issues/6341 | ExploitIssue TrackingPatch | |
| https://lists.debian.org/debian-lts-announce/2024/02/msg00007.html | mailing-listMailing ListThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UFQJCYJ23HWHNDOVKBHZQ7HCXXL6MM3/ | vendor-advisoryMailing ListThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2ZUHZXQ2C3JZYKPW4XHCMVVL467MA2V/ | vendor-advisoryMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-34151 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-34151 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 30, 2023
Updated Aug 2, 2024
Reserved May 29, 2023
Link CVE-2023-34151
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2023-38251 Assigner redhat
Published May 30, 2023
Updated Aug 2, 2024
Exploited since n/a
Link EUVD-2023-38251