Vulnerabilities > CVE-2022-32547 - Incorrect Type Conversion or Cast vulnerability in multiple products

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH

Summary

In ImageMagick, there is load of misaligned address for type 'double', which requires 8 byte alignment and for type 'float', which requires 4 byte alignment at MagickCore/property.c. Whenever crafted or untrusted input is processed by ImageMagick, this causes a negative impact to application availability or other problems related to undefined behavior.

Vulnerable Configurations

Part Description Count
Application
Imagemagick
1133
OS
Redhat
2
OS
Fedoraproject
1

Common Weakness Enumeration (CWE)