UBUNTU-CVE-2022-32547
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-32547
UBUNTU-CVE-2022-32547
Summary:
Details: In ImageMagick, there is load of misaligned address for type 'double', which requires 8 byte alignment and for type 'float', which requires 4 byte alignment at MagickCore/property.c. Whenever crafted or untrusted input is processed by ImageMagick, this causes a negative impact to application availability or other problems related to undefined behavior.
References: https://ubuntu.com/security/CVE-2022-32547, https://bugzilla.redhat.com/show_bug.cgi?id=2091813, https://github.com/ImageMagick/ImageMagick/issues/5033, https://github.com/ImageMagick/ImageMagick/pull/5034, https://github.com/ImageMagick/ImageMagick/commit/eac8ce4d873f28bb6a46aa3a662fb196b49b95d0, https://github.com/ImageMagick/ImageMagick6/commit/dc070da861a015d3c97488fdcca6063b44d47a7b, https://github.com/ImageMagick/ImageMagick6/commit/dc070da861a015d3c97488fdcca6063b44d47a7b, https://github.com/ImageMagick/ImageMagick/commit/eac8ce4d873f28bb6a46aa3a662fb196b49b95d0, https://ubuntu.com/security/notices/USN-5534-1, https://ubuntu.com/security/notices/USN-5736-1, https://ubuntu.com/security/notices/USN-5736-2, https://ubuntu.com/security/notices/USN-6200-1, https://www.cve.org/CVERecord?id=CVE-2022-32547
Affected packages
Package
Name: imagemagick
Purl: pkg:deb/ubuntu/imagemagick@8:6.7.7.10-6ubuntu3.13+esm3?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
