CVE-2022-44268: Infoleak
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded the content of an arbitrary. file (if the magick binary has permissions to read it).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-44268?
CVE-2022-44268 is a vulnerability in ImageMagick 7.1.0-49 that allows for information disclosure when parsing a PNG image.
How does CVE-2022-44268 work?
When ImageMagick parses a PNG image for resize, it can result in the embedded content of an arbitrary file being included in the resulting image.
What is the severity of CVE-2022-44268?
The severity of CVE-2022-44268 is medium, with a severity value of 6.5.
Which software versions are affected by CVE-2022-44268?
ImageMagick versions 7.1.0-49 are affected by CVE-2022-44268.
How can I fix CVE-2022-44268?
Update ImageMagick to version 8:6.9.10.23+dfsg-2.1+deb10u5, 8:6.9.11.60+dfsg-1.3+deb11u1, or 8:6.9.11.60+dfsg-1.6, depending on your system.