ImageMagick 7.x < 7.0.4-3 Multiple Vulnerabilities

high Nessus Plugin ID 96447

Synopsis

An application installed on the remote Windows host is affected by multiple vulnerabilities.

Description

The version of ImageMagick installed on the remote Windows host is 7.x prior to 7.0.4-3. It is, therefore, affected by multiple vulnerabilities :

- A denial of service vulnerability exists in the ReadTIFFImage() function in tiff.c due to improper handling of TIFF files. An unauthenticated, remote attacker can exploit this, by convincing a user to open a specially crafted TIFF file, to cause a denial of service condition or the disclosure of memory contents.

- A remote code execution vulnerability in the ReadPSDLayers() function in psd.c due to improper validation of PSB files. An unauthenticated, remote attacker can exploit this, by convincing a user to open a specially crafted PSD file, to cause a denial of service condition or the execution of arbitrary code.

Solution

Upgrade to ImageMagick version 7.0.4-3 or later. Note that you may also need to manually uninstall the vulnerable version from the system.

See Also

http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=31161

https://github.com/ImageMagick/ImageMagick/issues/347

Plugin Details

Severity: High

ID: 96447

File Name: imagemagick_7_0_4_3.nasl

Version: 1.7

Type: local

Agent: windows

Family: Windows

Published: 1/12/2017

Updated: 7/7/2023

Supported Sensors: Nessus Agent, Nessus

Risk Information

CVSS Score Rationale: Manual analysis of the vulnerability

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 6.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS Score Source: manual

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:imagemagick:imagemagick

Required KB Items: installed_sw/ImageMagick

Patch Publication Date: 1/7/2017

Vulnerability Publication Date: 1/5/2017