A heap-based-buffer-over-read flaw was found in ImageMagick's GetPixelAlpha() function of 'pixel-accessor.h'. This vulnerability is triggered when an attacker passes a specially crafted Tagged Image File Format (TIFF) image to convert it into a PICON file format. This issue can potentially lead to a denial of service and information disclosure.
[
{
"signature_version": "v1",
"source": "https://github.com/imagemagick/imagemagick/commit/e50f19fd73c792ebe912df8ab83aa51a243a3da7",
"deprecated": false,
"id": "CVE-2022-0284-60534e20",
"target": {
"function": "WritePICONImage",
"file": "coders/xpm.c"
},
"digest": {
"function_hash": "252425566050560855263177976518073506626",
"length": 7880.0
},
"signature_type": "Function"
},
{
"signature_version": "v1",
"source": "https://github.com/imagemagick/imagemagick/commit/e50f19fd73c792ebe912df8ab83aa51a243a3da7",
"deprecated": false,
"id": "CVE-2022-0284-6edf2fec",
"target": {
"file": "coders/xpm.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"87797395018650578211231814916421761121",
"200106990445893197953560268294270841294",
"95033872146013753876397730148199448005",
"41368052442698052330347212203678365153",
"87797395018650578211231814916421761121",
"201884265620066507831964570507506796376",
"107880667450026525286913478423459820960",
"328039202767865005710053993471843480653"
]
},
"signature_type": "Line"
}
]