RULE(RULE ID:337827)

Rule General Information
Release Date: 2024-02-27
Rule Name: ImageMagick 7.1.0-51 Denial of Service Vulnerability (CVE-2022-44267)
Severity:
CVE ID:
Rule Protection Details
Description: ImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parses a PNG image (e.g., for resize), the convert process could be left waiting for stdin input.
Impact: An attacker can launch a denial of service attack by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference: https://www.metabaseq.com/imagemagick-zero-days/
https://www.debian.org/security/2023/dsa-5347
https://lists.fedoraproject.org/archives/list/package-announce
https://lists.debian.org/debian-lts-announce/2023/03/msg00008.html
Solutions
Refer to the announcement or patch by the vendor: https://imagemagick.org/script/download.php