A flaw was found in ImageMagick where it did not properly sanitize certain input before using it to invoke convert processes. This flaw allows an attacker to create a specially crafted image that leads to a use-after-free vulnerability when processed by ImageMagick. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
[
{
"source": "https://github.com/imagemagick/imagemagick/commit/82775af03bbb10a0a1d0e15c0156c75673b4525e",
"target": {
"function": "ReadDCMImage",
"file": "coders/dcm.c"
},
"id": "CVE-2021-3962-4c4a4a80",
"deprecated": false,
"digest": {
"function_hash": "168201234120825407045811356471052558232",
"length": 28099.0
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"source": "https://github.com/imagemagick/imagemagick/commit/82775af03bbb10a0a1d0e15c0156c75673b4525e",
"target": {
"file": "coders/dcm.c"
},
"id": "CVE-2021-3962-d545a7c7",
"deprecated": false,
"digest": {
"line_hashes": [
"96365956146326091874962122126684256162",
"32941904576902578390634455902709202179",
"175020562535202099546215091863215473795",
"204637689310248593106512844224599847026",
"31196623183621358262108349599421664569",
"199031081146211321297465123523238945430",
"195907706849790379440031066911105007962"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
}
]