Lack of data validation - Path Traversal In imagemagick
Description
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded the content of an arbitrary. file (if the magick binary has permissions to read it).
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 8:6.9.11.60+dfsg-1.3+deb11u1 | ||
debian 12 | 8:6.9.11.60+dfsg-1.6 | ||
debian 13 | 8:6.9.11.60+dfsg-1.6 | ||
debian 14 | 8:6.9.11.60+dfsg-1.6 | ||
rpm rhel6 | - | - | |
rpm rhel7 | - | - |
Aliases
1. 2. 3. 4. 5.
References
1.