CVE-2012-0247

ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset and count values in the ResolutionUnit tag in the EXIF IFD0 of an image.
References
Link Resource
http://rhn.redhat.com/errata/RHSA-2012-0544.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-0545.html Third Party Advisory
http://secunia.com/advisories/47926 Broken Link
http://secunia.com/advisories/48247 Broken Link
http://secunia.com/advisories/48259 Broken Link
http://secunia.com/advisories/49043 Broken Link
http://secunia.com/advisories/49063 Broken Link
http://secunia.com/advisories/49068 Broken Link
http://ubuntu.com/usn/usn-1435-1 Third Party Advisory
http://www.cert.fi/en/reports/2012/vulnerability595210.html Broken Link
http://www.debian.org/security/2012/dsa-2427 Third Party Advisory
http://www.gentoo.org/security/en/glsa/glsa-201203-09.xml Third Party Advisory
http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=20286 Issue Tracking Patch Vendor Advisory
http://www.osvdb.org/79003 Broken Link
http://www.securitytracker.com/id?1027032 Third Party Advisory VDB Entry
http://rhn.redhat.com/errata/RHSA-2012-0544.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-0545.html Third Party Advisory
http://secunia.com/advisories/47926 Broken Link
http://secunia.com/advisories/48247 Broken Link
http://secunia.com/advisories/48259 Broken Link
http://secunia.com/advisories/49043 Broken Link
http://secunia.com/advisories/49063 Broken Link
http://secunia.com/advisories/49068 Broken Link
http://ubuntu.com/usn/usn-1435-1 Third Party Advisory
http://www.cert.fi/en/reports/2012/vulnerability595210.html Broken Link
http://www.debian.org/security/2012/dsa-2427 Third Party Advisory
http://www.gentoo.org/security/en/glsa/glsa-201203-09.xml Third Party Advisory
http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=20286 Issue Tracking Patch Vendor Advisory
http://www.osvdb.org/79003 Broken Link
http://www.securitytracker.com/id?1027032 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:11.04:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*

Configuration 4 (hide)

OR cpe:2.3:a:redhat:storage:2.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:6.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:6.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:6.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2012-06-05 22:55

Updated : 2025-04-11 00:51


NVD link : CVE-2012-0247

Mitre link : CVE-2012-0247

CVE.ORG link : CVE-2012-0247


JSON object : View

Products Affected

redhat

  • enterprise_linux_workstation
  • storage
  • enterprise_linux_server_aus
  • enterprise_linux_eus
  • enterprise_linux_server_eus
  • enterprise_linux_desktop
  • enterprise_linux_server

imagemagick

  • imagemagick

debian

  • debian_linux

canonical

  • ubuntu_linux
CWE
CWE-20

Improper Input Validation