ImageMagick, CLAHE Integer Underflow & Division-by-Zero, CVE-2022-44268 (Critical)

Listen to this Post

How the mentioned CVE works:

The vulnerability resides in the Contrast-Limited Adaptive Histogram Equalization (CLAHE) function in MagickCore/enhance.c. The core issue is a lack of validation for tile dimensions. When a tile’s width or height is zero, two distinct flaws are triggered. First, an unsigned integer underflow occurs when calculating tile_info.height - 1. If `tile_info.height` is zero, this operation wraps to a maximum value (UINT_MAX). This huge value is then used in pointer arithmetic for memory access, leading to massive out-of-bounds reads or writes, corrupting memory and causing segmentation faults or excessive memory allocation (Denial-of-Service). Second, the same zero value is used in division and modulus operations (% tile_info.height, / tile_info.width), causing a division-by-zero error that crashes the application. An attacker can easily trigger these conditions via the command line using `-clahe 0x0` or by processing a very small image where the auto-calculated tile size becomes zero.
Platform: ImageMagick
Version: 7.1.2-8
Vulnerability : Integer Underflow
Severity: Critical
date: 2022

Prediction: 2022-12-15

What Undercode Say:

./magick xc:black -clahe 0x0 null:
./magick -size 10x10 xc:black -clahe 0x0 null:
p += (ptrdiff_t) clahe_info->width (tile.height - 1);
if ((image->rows % tile_info.height) != 0)

How Exploit:

`-clahe 0x0`

`-clahe 0x0!`

Upload small image

Protection from this CVE:

Patch ImageMagick

Input validation

Bounds checking

Impact:

Denial-of-Service

Memory Corruption

Possible RCE

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top