Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-49219

Опубликовано: 10 июн. 2026
Источник: debian

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect parsing of the filename can result in a policy bypass and read files disallowed by a security policy using a symlink. This issue has been patched in versions 6.9.13-48 and 7.1.2-24.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
imagemagickfixed8:7.1.2.24+dfsg1-1package
imagemagicknot-affectedbookwormpackage
imagemagicknot-affectedbullseyepackage

Примечания

  • https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-xcjm-wqff-m669

  • Fixed by: https://github.com/ImageMagick/ImageMagick/commit/d1bf6bcf357fef944280263892dadf84fbb2211d (7.1.2-24)

  • Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/ac84db0cfd4891c0474b7bfdd3c1d016aa57216a (6.9.13-49)

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 месяцев назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect parsing of the filename can result in a policy bypass and read files disallowed by a security policy using a symlink. This issue has been patched in versions 6.9.13-48 and 7.1.2-24.

CVSS3: 4.2
redhat
около 2 месяцев назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect parsing of the filename can result in a policy bypass and read files disallowed by a security policy using a symlink. This issue has been patched in versions 6.9.13-48 and 7.1.2-24.

CVSS3: 5.5
nvd
около 2 месяцев назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect parsing of the filename can result in a policy bypass and read files disallowed by a security policy using a symlink. This issue has been patched in versions 6.9.13-48 and 7.1.2-24.

CVSS3: 5.5
redos
23 дня назад

Уязвимость ImageMagick7

CVSS3: 5.5
redos
23 дня назад

Уязвимость ImageMagick