← back
CVE-2022-1115

CVE-2022-1115

EPSS 0.6%CWE-119
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
29 Aug 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A heap-buffer-overflow flaw was found in ImageMagick’s PushShortPixel() function of quantum-private.h file. This vulnerability is triggered when an attacker passes a specially crafted TIFF image file to ImageMagick for conversion, potentially leading to a denial of service.
Affected products
n/a · ImageMagick