CVE Vulnerabilities

CVE-2012-0248

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Jun 05, 2012 | Modified: Apr 11, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
6.8 MODERATE
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

NameVendorStart VersionEnd Version
ImagemagickImagemagick*6.7.5-7 (including)
Red Hat Enterprise Linux 5RedHatImageMagick-0:6.2.8.0-15.el5_8*
Red Hat Enterprise Linux 6RedHatImageMagick-0:6.5.4.7-6.el6_2*
ImagemagickUbuntudevel*
ImagemagickUbuntuhardy*
ImagemagickUbuntulucid*
ImagemagickUbuntumaverick*
ImagemagickUbuntunatty*
ImagemagickUbuntuoneiric*
ImagemagickUbuntuprecise*
ImagemagickUbuntuupstream*

References