A heap-based buffer overflow issue was found in ImageMagick's PushCharPixel() function in quantum-private.h. This issue may allow a local attacker to trick the user into opening a specially crafted file, triggering an out-of-bounds read error and allowing an application to crash, resulting in a denial of service.
{
"cna_assigner": "redhat",
"cwe_ids": [
"CWE-125"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/3xxx/CVE-2023-3745.json"
}{
"extracted_events": [
{
"introduced": "7.0.0-0"
},
{
"fixed": "7.0.10-0"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
],
"cpe": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-3745.json"
[
{
"target": {
"function": "ReadTIFFImage",
"file": "coders/tiff.c"
},
"deprecated": false,
"source": "https://github.com/imagemagick/imagemagick/commit/54cdc146bbe50018526770be201b56643ad58ba7",
"id": "CVE-2023-3745-0fc8b379",
"signature_version": "v1",
"digest": {
"length": 22362.0,
"function_hash": "148769445397280588461867256646424347782"
},
"signature_type": "Function"
},
{
"target": {
"function": "ReadTIFFImage",
"file": "coders/tiff.c"
},
"deprecated": false,
"source": "https://github.com/imagemagick/imagemagick/commit/651672f19c75161a6159d9b6838fd3095b6c5304",
"id": "CVE-2023-3745-3691a2d6",
"signature_version": "v1",
"digest": {
"length": 22406.0,
"function_hash": "280077603883983449602804815327969271080"
},
"signature_type": "Function"
},
{
"target": {
"file": "coders/pdf.c"
},
"deprecated": false,
"source": "https://github.com/imagemagick/imagemagick/commit/00c3687ccca2bbc61bb117c28a6a689410693060",
"id": "CVE-2023-3745-6885936e",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"267088119790984257781778290784893837609",
"104586599622970597080585580560734579041",
"314242282688843173384374917212345720778",
"136651148297210183770076042970878253946"
]
},
"signature_type": "Line"
},
{
"target": {
"file": "coders/tiff.c"
},
"deprecated": false,
"source": "https://github.com/imagemagick/imagemagick/commit/651672f19c75161a6159d9b6838fd3095b6c5304",
"id": "CVE-2023-3745-d6ea5ce0",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"118824816895528287798113084228650057011",
"330836052793523869897681511012797318436",
"68125290772832173454986644648354935781",
"61239350792466514650104050197438222833",
"232192484066260492618245841682257617122",
"183138322953951099720810700417921294079",
"100517629411598991239095207334309534843",
"23811094227217603236953172319967586336",
"305569056091343756016595704207853994615"
]
},
"signature_type": "Line"
},
{
"target": {
"function": "WritePDFImage",
"file": "coders/pdf.c"
},
"deprecated": false,
"source": "https://github.com/imagemagick/imagemagick/commit/00c3687ccca2bbc61bb117c28a6a689410693060",
"id": "CVE-2023-3745-fa511610",
"signature_version": "v1",
"digest": {
"length": 48687.0,
"function_hash": "212123256541805407061688552405177200280"
},
"signature_type": "Function"
}
]
"2026-08-12T14:50:50Z"
{
"extracted_events": [
{
"introduced": "6.0"
},
{
"fixed": "6.9-11-0"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
],
"cpe": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*"
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-3745.json"
[
{
"target": {
"file": "coders/tiff.c"
},
"deprecated": false,
"source": "https://github.com/imagemagick/imagemagick6/commit/7486477aa00c5c7856b111506da075b6cdfa8b73",
"id": "CVE-2023-3745-56e520bd",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"129575627178515815325741093493251190489",
"181544294095345802565870614676011298339",
"164215297617223026395716653487651170959",
"251454235028671124042236441957587586424",
"232192484066260492618245841682257617122",
"183138322953951099720810700417921294079",
"100517629411598991239095207334309534843",
"23811094227217603236953172319967586336",
"305569056091343756016595704207853994615"
]
},
"signature_type": "Line"
},
{
"target": {
"function": "ReadTIFFImage",
"file": "coders/tiff.c"
},
"deprecated": false,
"source": "https://github.com/imagemagick/imagemagick6/commit/7486477aa00c5c7856b111506da075b6cdfa8b73",
"id": "CVE-2023-3745-c37c045e",
"signature_version": "v1",
"digest": {
"length": 22168.0,
"function_hash": "150452053484788551458709260928417487066"
},
"signature_type": "Function"
},
{
"target": {
"function": "ReadTIFFImage",
"file": "coders/tiff.c"
},
"deprecated": false,
"source": "https://github.com/imagemagick/imagemagick6/commit/b466a96965afc1308a4ace93f5535c2b770f294b",
"id": "CVE-2023-3745-e356b37a",
"signature_version": "v1",
"digest": {
"length": 22124.0,
"function_hash": "201658892558676292037072503713412344059"
},
"signature_type": "Function"
}
]
"2026-08-12T14:50:50Z"