A heap-buffer-overflow flaw was found in ImageMagick’s PushShortPixel() function of quantum-private.h file. This vulnerability is triggered when an attacker passes a specially crafted TIFF image file to ImageMagick for conversion, potentially leading to a denial of service.
[ { "signature_type": "Function", "deprecated": false, "source": "https://github.com/imagemagick/imagemagick/commit/c8718305f120293d8bf13724f12eed885d830b09", "signature_version": "v1", "target": { "function": "ReadTIFFImage", "file": "coders/tiff.c" }, "digest": { "function_hash": "53091239174139112229880907995831957069", "length": 23619.0 }, "id": "CVE-2022-1115-9aa89b3e" }, { "signature_type": "Line", "deprecated": false, "source": "https://github.com/imagemagick/imagemagick6/commit/1f860f52bd8d58737ad883072203391096b30b51", "signature_version": "v1", "target": { "file": "coders/tiff.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "252132400079984166500888260826723203934", "148854561404294017165234745221039342872", "30582049300567466879120243385472620889", "299651691814447263112547392134213845045" ] }, "id": "CVE-2022-1115-9d71acb4" }, { "signature_type": "Line", "deprecated": false, "source": "https://github.com/imagemagick/imagemagick/commit/c8718305f120293d8bf13724f12eed885d830b09", "signature_version": "v1", "target": { "file": "coders/tiff.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "252132400079984166500888260826723203934", "148854561404294017165234745221039342872", "30582049300567466879120243385472620889", "299651691814447263112547392134213845045" ] }, "id": "CVE-2022-1115-b5d4ff4c" }, { "signature_type": "Function", "deprecated": false, "source": "https://github.com/imagemagick/imagemagick6/commit/1f860f52bd8d58737ad883072203391096b30b51", "signature_version": "v1", "target": { "function": "ReadTIFFImage", "file": "coders/tiff.c" }, "digest": { "function_hash": "38674790809880929554605923442809967867", "length": 23555.0 }, "id": "CVE-2022-1115-e7572997" } ]