A heap-based buffer overflow issue was found in ImageMagick's PushCharPixel() function in quantum-private.h. This issue may allow a local attacker to trick the user into opening a specially crafted file, triggering an out-of-bounds read error and allowing an application to crash, resulting in a denial of service.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-3745.json"
[
{
"signature_version": "v1",
"id": "CVE-2023-3745-6885936e",
"source": "https://github.com/imagemagick/imagemagick/commit/00c3687ccca2bbc61bb117c28a6a689410693060",
"digest": {
"threshold": 0.9,
"line_hashes": [
"267088119790984257781778290784893837609",
"104586599622970597080585580560734579041",
"314242282688843173384374917212345720778",
"136651148297210183770076042970878253946"
]
},
"target": {
"file": "coders/pdf.c"
},
"signature_type": "Line",
"deprecated": false
},
{
"signature_version": "v1",
"id": "CVE-2023-3745-fa511610",
"source": "https://github.com/imagemagick/imagemagick/commit/00c3687ccca2bbc61bb117c28a6a689410693060",
"digest": {
"function_hash": "212123256541805407061688552405177200280",
"length": 48687.0
},
"target": {
"file": "coders/pdf.c",
"function": "WritePDFImage"
},
"signature_type": "Function",
"deprecated": false
}
]