CVE-2023-34152: Input Validation
A vulnerability was found in ImageMagick. This issue can allow remote code execution in OpenBlob with --enable-pipes configured.
Other sources
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.
RCE (shell command injection) vulnerability in OpenBlob with --enable-pipes configured https://github.com/ImageMagick/ImageMagick/issues/6339
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-34152?
The severity of CVE-2023-34152 is critical.
How does CVE-2023-34152 impact ImageMagick?
CVE-2023-34152 can cause a remote code execution vulnerability in ImageMagick's OpenBlob function when --enable-pipes is configured.
Which versions of ImageMagick are affected by CVE-2023-34152?
ImageMagick versions up to and excluding 7.1.1.11 are affected by CVE-2023-34152.
How can I fix CVE-2023-34152 in ImageMagick?
Apply the latest security patch or update to a version of ImageMagick that is not affected by CVE-2023-34152.
Where can I find more information about CVE-2023-34152?
You can find more information about CVE-2023-34152 on the GitHub issue, Red Hat Security Advisory, and Bugzilla links provided.