
Cloud Vulnerability DB
A community-led vulnerabilities database
A heap-buffer-overflow vulnerability (CVE-2022-1115) was discovered in ImageMagick's PushShortPixel() function within the quantum-private.h file. The vulnerability is triggered when processing specially crafted TIFF image files for conversion. This vulnerability affects ImageMagick versions prior to 6.9.12-44 and 7.1.0-29 (CVE Details, Mitre CVE).
The vulnerability occurs in the PushShortPixel function of quantum-private.h when processing TIFF images. The issue stems from improper memory allocation and buffer management during the image conversion process. The bug was specifically identified in the memory allocation for tile processing, where the extent calculation needed to be adjusted by a factor of 4 to prevent the overflow (GitHub Commit, GitHub Issue).
When exploited, this vulnerability can lead to a denial of service condition through heap buffer overflow. The issue affects systems processing TIFF images using vulnerable versions of ImageMagick (Debian Tracker).
The vulnerability has been fixed in ImageMagick versions 6.9.12-44 and 7.1.0-29. Users are advised to upgrade to these or later versions. The fix involves adjusting the memory allocation calculation in the TIFF processing code (GitHub Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."