Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted IOP tag offsets in the IFD in an image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0248.
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Imagemagick | Imagemagick | * | 6.7.5-8 (including) |
Imagemagick | Ubuntu | devel | * |
Imagemagick | Ubuntu | hardy | * |
Imagemagick | Ubuntu | lucid | * |
Imagemagick | Ubuntu | natty | * |
Imagemagick | Ubuntu | oneiric | * |
Imagemagick | Ubuntu | precise | * |