Imagemagick: heap-buffer-overflow in coders/tiff.c
Description
Heap-buffer-overflow in ImageMagick's TIFF coder allows denial of service via crafted file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Heap-buffer-overflow in ImageMagick's TIFF coder allows denial of service via crafted file.
Vulnerability
A heap-based buffer overflow vulnerability exists in the coders/tiff.c file of ImageMagick versions up to and including 7.1.1 [1][2]. The flaw occurs when processing specially crafted TIFF images, leading to memory corruption.
Exploitation
Exploitation requires the attacker to convince a user to open a malicious TIFF file using ImageMagick or an application leveraging it. No authentication or network access is needed; the attack is local and depends on user interaction [1].
Impact
Successful exploitation results in an application crash, causing a denial of service. No code execution or data disclosure has been reported [1].
Mitigation
The fix is available in a commit [2] and is included in ImageMagick versions after 7.1.1. Users should update to the latest version. No workaround is documented.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
8cpe:/o:redhat:enterprise_linux:6+ 1 more
- cpe:/o:redhat:enterprise_linux:6
- cpe:/o:redhat:enterprise_linux:7
- osv-coords5 versionspkg:apk/chainguard/imagemagick-6pkg:apk/chainguard/imagemagick-6-devpkg:apk/chainguard/imagemagick-6-docpkg:apk/chainguard/imagemagick-6-staticpkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Tumbleweed
< 0+ 4 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 7.1.1.12-1.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- access.redhat.com/security/cve/CVE-2023-3428mitrevdb-entryx_refsource_REDHAT
- bugzilla.redhat.com/show_bug.cgimitreissue-trackingx_refsource_REDHAT
News mentions
0No linked articles in our index yet.