A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.
{ "vanir_signatures": [ { "signature_type": "Line", "digest": { "threshold": 0.9, "line_hashes": [ "151150098313691558966789840033230653481", "153218788397097334813751225780231635941", "271086338835071861133624358271567747546", "112749370230066917425780743551720670016", "107049740592164306293298141409052860617" ] }, "id": "CVE-2023-1906-167454da", "deprecated": false, "source": "https://github.com/imagemagick/imagemagick6/commit/e30c693b37c3b41723f1469d1226a2c814ca443d", "signature_version": "v1", "target": { "file": "coders/tiff.c" } }, { "signature_type": "Function", "digest": { "length": 23604.0, "function_hash": "149476755812666217664135650598740949751" }, "id": "CVE-2023-1906-195d1b52", "deprecated": false, "source": "https://github.com/imagemagick/imagemagick/commit/d7a8bdd7bb33cf8e58bc01b4a4f2ea5466f8c6b3", "signature_version": "v1", "target": { "function": "ReadTIFFImage", "file": "coders/tiff.c" } }, { "signature_type": "Line", "digest": { "threshold": 0.9, "line_hashes": [ "151150098313691558966789840033230653481", "296310619011704825071303630096226686489", "171367926610456084490699054566304259528", "315707733254325176249062617782103364686", "18065814098927483271360742095403979758" ] }, "id": "CVE-2023-1906-8026f19d", "deprecated": false, "source": "https://github.com/imagemagick/imagemagick/commit/d7a8bdd7bb33cf8e58bc01b4a4f2ea5466f8c6b3", "signature_version": "v1", "target": { "file": "coders/tiff.c" } }, { "signature_type": "Function", "digest": { "length": 23433.0, "function_hash": "121795050214466308353526682305693204968" }, "id": "CVE-2023-1906-f79ffe68", "deprecated": false, "source": "https://github.com/imagemagick/imagemagick6/commit/e30c693b37c3b41723f1469d1226a2c814ca443d", "signature_version": "v1", "target": { "function": "ReadTIFFImage", "file": "coders/tiff.c" } } ] }