Medium severity6.2NVD Advisory· Published Oct 4, 2023· Updated Jun 17, 2026
CVE-2023-3428
CVE-2023-3428
Description
A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local attacker to trick the user into opening a specially crafted file, resulting in an application crash and denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11- osv-coords5 versionspkg:apk/chainguard/imagemagick-6-staticpkg:apk/chainguard/imagemagick-6pkg:apk/chainguard/imagemagick-6-devpkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Tumbleweedpkg:apk/chainguard/imagemagick-6-doc
< 0+ 4 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 7.1.1.12-1.1
- (no CPE)range: < 0
(expand)+ 1 more
- (no CPE)
- cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*range: <7.1.1-19
cpe:/o:redhat:enterprise_linux:6+ 1 more
- cpe:/o:redhat:enterprise_linux:6
- cpe:/o:redhat:enterprise_linux:7
- cpe:2.3:a:fedoraproject:extra_packages_for_enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- access.redhat.com/security/cve/CVE-2023-3428nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.