Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2021-3596

Published: 24 February 2022

A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not checking the return value from libxml2's xmlCreatePushParserCtxt() and uses the value directly, which leads to a crash and segmentation fault.

Notes

AuthorNote
alexmurray
According to debian this only affects imagemagick7 but looking at the code and the patch I suspect the older versions shipped in Ubuntu are also vulnerable.
eslerm
only affects creating PS/PDF file which policy.xml forbids (tested)

Priority

Low

Cvss 3 Severity Score

6.5

Score breakdown

Status

Package Release Status
imagemagick
Launchpad, Ubuntu, Debian
bionic Not vulnerable
(policy forbids PS/PDF)
focal Not vulnerable
(policy forbids PS/PDF)
impish Not vulnerable
(8:6.9.11.60+dfsg-1ubuntu1)
jammy Not vulnerable
(8:6.9.11.60+dfsg-1.3build1)
kinetic Not vulnerable
(8:6.9.11.60+dfsg-1.3build1)
trusty Not vulnerable
(policy forbids PS/PDF)
upstream Not vulnerable
(debian: Specific to IM7)
xenial Not vulnerable
(policy forbids PS/PDF)
Patches:
upstream: https://github.com/ImageMagick/ImageMagick6/commit/27f314e2e6eb44b661e65008ce1ce46b85a5628b
upstream: https://github.com/ImageMagick/ImageMagick/commit/43dfb1894761c4929d5d5c98dc80ba4e59a0d114

Severity score breakdown

Parameter Value
Base score 6.5
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Scope Unchanged
Confidentiality None
Integrity impact None
Availability impact High
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H