CVE-2022-32547
Published: 16 June 2022
Summary
CVE-2022-32547 is a high-severity Incorrect Type Conversion or Cast (CWE-704) vulnerability in Imagemagick Imagemagick. Its CVSS base score is 7.8 (High).
Operationally, ranked at the 27.8th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2022-35615
Vulnerability details
In ImageMagick, there is load of misaligned address for type 'double', which requires 8 byte alignment and for type 'float', which requires 4 byte alignment at MagickCore/property.c. Whenever crafted or untrusted input is processed by ImageMagick, this causes a negative…
more
impact to application availability or other problems related to undefined behavior.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.