logo

Database

Insecure generation of random numbers In magick.net-q16-anycpu

Description

ImageMagick: Information Disclosure in PasskeyEncipherImage via AES-CTR nonce reuse The PasskeyEncipherImage method is vulnerable to information disclosure via AES-CTR nonce reuse. ImageMagick has update the documentation on its website to make it more clear that this is happening: https://imagemagick.org/cipher/

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions

1-10 of 17

10