A heap-buffer-overflow flaw was found in ImageMagick’s PushShortPixel() function of quantum-private.h file. This vulnerability is triggered when an attacker passes a specially crafted TIFF image file to ImageMagick for conversion, potentially leading to a denial of service.
[
{
"id": "CVE-2022-1115-9aa89b3e",
"source": "https://github.com/imagemagick/imagemagick/commit/c8718305f120293d8bf13724f12eed885d830b09",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"function_hash": "53091239174139112229880907995831957069",
"length": 23619.0
},
"target": {
"function": "ReadTIFFImage",
"file": "coders/tiff.c"
}
},
{
"id": "CVE-2022-1115-b5d4ff4c",
"source": "https://github.com/imagemagick/imagemagick/commit/c8718305f120293d8bf13724f12eed885d830b09",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"252132400079984166500888260826723203934",
"148854561404294017165234745221039342872",
"30582049300567466879120243385472620889",
"299651691814447263112547392134213845045"
]
},
"target": {
"file": "coders/tiff.c"
}
}
]
[
{
"id": "CVE-2022-1115-9d71acb4",
"source": "https://github.com/imagemagick/imagemagick6/commit/1f860f52bd8d58737ad883072203391096b30b51",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"252132400079984166500888260826723203934",
"148854561404294017165234745221039342872",
"30582049300567466879120243385472620889",
"299651691814447263112547392134213845045"
]
},
"target": {
"file": "coders/tiff.c"
}
},
{
"id": "CVE-2022-1115-e7572997",
"source": "https://github.com/imagemagick/imagemagick6/commit/1f860f52bd8d58737ad883072203391096b30b51",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"function_hash": "38674790809880929554605923442809967867",
"length": 23555.0
},
"target": {
"function": "ReadTIFFImage",
"file": "coders/tiff.c"
}
}
]