Vulnerabilities > CVE-2022-1114 - Use After Free vulnerability in Imagemagick

047910
CVSS 7.1 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
HIGH
local
low complexity
imagemagick
CWE-416

Summary

A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm.c file. This vulnerability is triggered when an attacker passes a specially crafted DICOM image file to ImageMagick for conversion, potentially leading to information disclosure and a denial of service.

Vulnerable Configurations

Part Description Count
Application
Imagemagick
1427

Common Weakness Enumeration (CWE)