Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2023-1289
Description:A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a remote attacker to pass a specially crafted SVG file that leads to a segmentation fault, generating many trash files in "/tmp," resulting in a denial of service. When ImageMagick crashes, it generates a lot of trash files. These trash files can be large if the SVG file contains many render actions. In a denial of service attack, if a remote attacker uploads an SVG file of size t, ImageMagick generates files of size 103*t. If an attacker uploads a 100M SVG, the server will generate about 10G.
Test IDs: 1.3.6.1.4.1.25623.1.1.10.2023.0136   1.3.6.1.4.1.25623.1.1.4.2023.1734.1  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2023-1289
https://bugzilla.redhat.com/show_bug.cgi?id=2176858
https://bugzilla.redhat.com/show_bug.cgi?id=2176858
https://github.com/ImageMagick/ImageMagick/commit/c5b23cbf2119540725e6dc81f4deb25798ead6a4
https://github.com/ImageMagick/ImageMagick/commit/c5b23cbf2119540725e6dc81f4deb25798ead6a4
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-j96m-mjp6-99xr
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-j96m-mjp6-99xr
https://lists.debian.org/debian-lts-announce/2024/02/msg00007.html




© 1998-2025 E-Soft Inc. All rights reserved.