First published: Mon May 29 2023(Updated: )
A vulnerability was found in ImageMagick. This issue can allow remote code execution in OpenBlob with --enable-pipes configured.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick ImageMagick | <7.1.1.11 | |
Fedoraproject Extra Packages For Enterprise Linux | =8.0 | |
Fedoraproject Fedora | =37 | |
Fedoraproject Fedora | =38 | |
Redhat Enterprise Linux | =6.0 | |
Redhat Enterprise Linux | =7.0 | |
ImageMagick ImageMagick | <7.1.1-11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-34152 is critical.
CVE-2023-34152 can cause a remote code execution vulnerability in ImageMagick's OpenBlob function when --enable-pipes is configured.
ImageMagick versions up to and excluding 7.1.1.11 are affected by CVE-2023-34152.
Apply the latest security patch or update to a version of ImageMagick that is not affected by CVE-2023-34152.
You can find more information about CVE-2023-34152 on the GitHub issue, Red Hat Security Advisory, and Bugzilla links provided.