Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-56377

Опубликовано: 30 июн. 2026
Источник: debian
EPSS Низкий

Описание

ImageMagick before 7.1.2-24 contains an incorrect policy check that allows attackers to create or truncate files disallowed by security policies. Remote attackers can bypass path policy restrictions in sandboxed conversion services to write arbitrary files outside intended boundaries.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
imagemagickfixed8:7.1.2.24+dfsg1-1package

Примечания

  • https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-gm48-c7f2-v67p

  • Fixed by: https://github.com/ImageMagick/ImageMagick/commit/3705205e1424d379c2fc46c026c8560ccea0509e (7.1.2-24)

  • Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/a2aa44ce71f0950522a104bbd4daa7b8a0b6709c (6.9.13-49)

EPSS

Процентиль: 6%
0.00164
Низкий

Связанные уязвимости

CVSS3: 3.3
ubuntu
3 месяца назад

ImageMagick before 7.1.2-24 contains an incorrect policy check that allows attackers to create or truncate files disallowed by security policies. Remote attackers can bypass path policy restrictions in sandboxed conversion services to write arbitrary files outside intended boundaries.

CVSS3: 3.3
redhat
3 месяца назад

ImageMagick before 7.1.2-24 contains an incorrect policy check that allows attackers to create or truncate files disallowed by security policies. Remote attackers can bypass path policy restrictions in sandboxed conversion services to write arbitrary files outside intended boundaries.

CVSS3: 3.3
nvd
3 месяца назад

ImageMagick before 7.1.2-24 contains an incorrect policy check that allows attackers to create or truncate files disallowed by security policies. Remote attackers can bypass path policy restrictions in sandboxed conversion services to write arbitrary files outside intended boundaries.

CVSS3: 3.3
redos
2 месяца назад

Уязвимость ImageMagick

CVSS3: 3.3
redos
2 месяца назад

Уязвимость ImageMagick7

EPSS

Процентиль: 6%
0.00164
Низкий