Medium severity6.2NVD Advisory· Published Oct 4, 2023· Updated Jun 17, 2026
CVE-2023-3428
CVE-2023-3428
Description
A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local attacker to trick the user into opening a specially crafted file, resulting in an application crash and denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:/o:redhat:enterprise_linux:6+ 1 more
- cpe:/o:redhat:enterprise_linux:6
- cpe:/o:redhat:enterprise_linux:7
- osv-coords5 versionspkg:apk/chainguard/imagemagick-6pkg:apk/chainguard/imagemagick-6-devpkg:apk/chainguard/imagemagick-6-docpkg:apk/chainguard/imagemagick-6-staticpkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Tumbleweed
< 0+ 4 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 7.1.1.12-1.1
Patches
Vulnerability mechanics
References
2- access.redhat.com/security/cve/CVE-2023-3428nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.