Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-34152

Опубликовано: 30 мая 2023
Источник: debian
EPSS Высокий

Описание

A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
imagemagickunfixedpackage

Примечания

  • https://github.com/ImageMagick/ImageMagick/issues/6339

  • Only an issue when configured with --enable-pipes. Enabling pipes are

  • a security risk per se and user needs to take precautions accordingly

  • when enabled.

  • https://github.com/ImageMagick/ImageMagick/issues/6339#issuecomment-1559698800

  • CVE might get rejected or disputed

EPSS

Процентиль: 99%
0.74515
Высокий

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 2 лет назад

A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.

CVSS3: 9.4
redhat
около 2 лет назад

A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.

CVSS3: 9.8
nvd
около 2 лет назад

A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.

github
около 2 лет назад

A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.

CVSS3: 9.8
fstec
около 2 лет назад

Уязвимость компонента OpenBlob консольного графического редактора ImageMagick, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 99%
0.74515
Высокий