CVE Vulnerabilities

CVE-2012-0248

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Jun 05, 2012 | Modified: Jul 31, 2020
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
6.8 MODERATE
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW

ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Imagemagick Imagemagick * 6.7.5-7 (including)
Red Hat Enterprise Linux 5 RedHat ImageMagick-0:6.2.8.0-15.el5_8 *
Red Hat Enterprise Linux 6 RedHat ImageMagick-0:6.5.4.7-6.el6_2 *
Imagemagick Ubuntu devel *
Imagemagick Ubuntu hardy *
Imagemagick Ubuntu lucid *
Imagemagick Ubuntu maverick *
Imagemagick Ubuntu natty *
Imagemagick Ubuntu oneiric *
Imagemagick Ubuntu precise *
Imagemagick Ubuntu upstream *

References