CVE-2021-3596
24.02.2022, 19:15
A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not checking the return value from libxml2's xmlCreatePushParserCtxt() and uses the value directly, which leads to a crash and segmentation fault.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| imagemagick | imagemagick | 𝑥 < 7.0.10-31 |
| redhat | enterprise_linux | 5.0 |
| redhat | enterprise_linux | 6.0 |
| redhat | enterprise_linux | 7.0 |
| debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| ImageMagick |
| ||
| ImageMagick-c++ |
| ||
| ImageMagick-c++-devel |
| ||
| ImageMagick-debuginfo |
| ||
| ImageMagick-devel |
| ||
| ImageMagick-doc |
| ||
| ImageMagick-perl |
|
Common Weakness Enumeration
References