Disclosure Date 2021/12/21

CVE-2021-4219

Remote Denial of Service (DoS) in ImageMagick

ImageMagick におけるサービス運用妨害 (DoS)

Credit

stypr (@stereotype32)

Affected-Versions

ImageMagick: v6.9.10-23 and earlier, v7.1.0-18 and lower

CWE

  • CWE-20

Description

Affected versions of this package are vulnerable to Denial of Service (DoS) via crafted SVG file which is submitted to the ImageMagick, to let ImageMagick hang forever from reading a file descriptor.

Back