CVE Database
/

CVE-2023-1906

Back to search

CVE-2023-1906

Published: Apr 12, 2023

Modified: Feb 10, 2025

PUBLISHED

Description

A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.

VendorProductVersions

n/a

ImageMagick

affected
Fixed in ImageMagick v6.9.12-84, v 7.1.1-6.

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now