Name | CVE-2021-3610 |
Description | A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-5628-1 |
Debian Bugs | 1037090 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
imagemagick (PTS) | jessie, jessie (lts) | 8:6.8.9.9-5+deb8u27 | fixed |
stretch (security) | 8:6.9.7.4+dfsg-11+deb9u14 | fixed | |
stretch (lts), stretch | 8:6.9.7.4+dfsg-11+deb9u20 | fixed | |
buster, buster (lts) | 8:6.9.10.23+dfsg-2.1+deb10u9 | fixed | |
buster (security) | 8:6.9.10.23+dfsg-2.1+deb10u7 | fixed | |
bullseye | 8:6.9.11.60+dfsg-1.3+deb11u4 | fixed | |
bullseye (security) | 8:6.9.11.60+dfsg-1.3+deb11u3 | fixed | |
bookworm | 8:6.9.11.60+dfsg-1.6+deb12u2 | fixed | |
bookworm (security) | 8:6.9.11.60+dfsg-1.6+deb12u1 | fixed | |
trixie | 8:6.9.13.12+dfsg1-1 | fixed | |
sid | 8:7.1.1.39+dfsg1-2 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
imagemagick | source | experimental | 8:6.9.12.20+dfsg1-1 | |||
imagemagick | source | jessie | (not affected) | |||
imagemagick | source | stretch | (not affected) | |||
imagemagick | source | buster | (not affected) | |||
imagemagick | source | bullseye | 8:6.9.11.60+dfsg-1.3+deb11u3 | DSA-5628-1 | ||
imagemagick | source | bookworm | 8:6.9.11.60+dfsg-1.6+deb12u1 | DSA-5628-1 | ||
imagemagick | source | (unstable) | 8:6.9.12.98+dfsg1-2 | 1037090 |
[buster] - imagemagick <not-affected> (Vulnerable code introduced later)
https://github.com/ImageMagick/ImageMagick/commit/930ff0d1a9bc42925a7856e9ea53f5fc9f318bf3
ImageMagick6 prerequisite for <= 6.9.10-92: https://github.com/ImageMagick/ImageMagick6/commit/2d96228eec9fbea62ddb6c1450fa8d43e2c6b68a
ImageMagick6 prerequisite for <= 6.9.11-10: https://github.com/ImageMagick/ImageMagick6/commit/7374894385161859ffbb84e280fcc89e7ae257e4
ImageMagick6 prerequisite for <= 6.9.11-54: https://github.com/ImageMagick/ImageMagick6/commit/cdb67005376bcc8cbb0b743fb22787794cd30ebc
ImageMagick6 [1/2]: https://github.com/ImageMagick/ImageMagick6/commit/b307bcadcdf6ea6819951ac1786b7904f27b25c6 (6.9.12-14)
ImageMagick6 [2/2]: https://github.com/ImageMagick/ImageMagick6/commit/c75ae771a00c38b757c5ef4b424b51e761b02552 (6.9.12-14)
Introduced by (Support 32-bit tiles TIFF images): https://github.com/ImageMagick/ImageMagick6/commit/b874d50070557eb98bdc6a3095ef4769af583dd2 (6.9.10-88)
[stretch] - imagemagick <not-affected> (code was introduced post buster)
[jessie] - imagemagick <not-affected> (code was introduced post buster)