
Cloud Vulnerability DB
A community-led vulnerabilities database
A heap-use-after-free vulnerability (CVE-2021-3962) was discovered in ImageMagick where it did not properly sanitize certain input before using it to invoke convert processes. The vulnerability was specifically identified in the RelinquishDCMMemory function within the dcm.c file. This issue affects ImageMagick version 7.1.0-14 and was fixed in version 7.1.0-15 (ImageMagick Issue, Red Hat Bugzilla).
The vulnerability is a heap-use-after-free issue that occurs in the RelinquishDCMMemory function within dcm.c. The bug manifests when attempting to access memory at address 0x60f000000580 after it has been freed. The issue was triggered during image conversion operations using specific parameters. The vulnerability was confirmed through ASAN (Address Sanitizer) testing, which revealed the exact location of the use-after-free condition (ImageMagick Issue).
When exploited, this vulnerability could lead to program crashes due to memory corruption. The issue manifests as a double free detection in tcache, which could potentially lead to denial of service conditions or possible code execution in certain circumstances (ImageMagick Issue).
The issue was fixed in ImageMagick version 7.1.0-15 by moving the free operation to the correct position in the code. Users should upgrade to this version or later to address the vulnerability. It's worth noting that ImageMagick6 is not affected by this vulnerability (Red Hat Bugzilla, ImageMagick Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."