First published: Mon Feb 06 2023(Updated: )
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded the content of an arbitrary. file (if the magick binary has permissions to read it).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/imagemagick | <=8:6.9.10.23+dfsg-2.1+deb10u1 | 8:6.9.10.23+dfsg-2.1+deb10u5 8:6.9.11.60+dfsg-1.3+deb11u1 8:6.9.11.60+dfsg-1.6 |
ImageMagick ImageMagick | =7.1.0-49 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-44268 is a vulnerability in ImageMagick 7.1.0-49 that allows for information disclosure when parsing a PNG image.
When ImageMagick parses a PNG image for resize, it can result in the embedded content of an arbitrary file being included in the resulting image.
The severity of CVE-2022-44268 is medium, with a severity value of 6.5.
ImageMagick versions 7.1.0-49 are affected by CVE-2022-44268.
Update ImageMagick to version 8:6.9.10.23+dfsg-2.1+deb10u5, 8:6.9.11.60+dfsg-1.3+deb11u1, or 8:6.9.11.60+dfsg-1.6, depending on your system.