Heap-buffer-overflow vulnerability in ImageMagick's PushShortPixel() function

Heap-buffer-overflow vulnerability in ImageMagick's PushShortPixel() function

CVE-2022-1115 · MEDIUM Severity

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

A heap-buffer-overflow flaw was found in ImageMagick’s PushShortPixel() function of quantum-private.h file. This vulnerability is triggered when an attacker passes a specially crafted TIFF image file to ImageMagick for conversion, potentially leading to a denial of service.

Learn more about our Web Application Penetration Testing UK.