Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-56379

Опубликовано: 23 июн. 2026
Источник: debian

Описание

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
imagemagickfixed8:7.1.2.15+dfsg1-1package
imagemagickfixed8:7.1.1.43+dfsg1-1+deb13u8trixiepackage
imagemagickfixed8:6.9.11.60+dfsg-1.6+deb12u8bookwormpackage
imagemagickfixed8:6.9.11.60+dfsg-1.3+deb11u11bullseyepackage

Примечания

  • https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-xpg8-7m6m-jf56

  • Fixed by: https://github.com/ImageMagick/ImageMagick/commit/f63c78b3828933f1cc7cf499390248981af765aa (7.1.2-14)

  • Fixed by: https://github.com/ImageMagick/ImageMagick/commit/9db96365ecab5de69cdec81b9359672b3a827aaa (7.1.2-14)

  • Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/4b7a043eb0fdf233ea9ecf237bcb009c16a354cd (6.9.13-39)

  • Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/b4a7adf48e723ab73d2337ada34ee0fee7337250 (6.9.13-39)

  • bookworm/bullseye fixed by backporting svg/msl coder from 6.9.13-41

  • trixie fixed by backporting svg/msl to 7.1.2-16

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 1 месяца назад

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.

CVSS3: 8.1
redhat
около 1 месяца назад

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.

CVSS3: 8.1
nvd
около 1 месяца назад

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.

suse-cvrf
4 дня назад

Security update for ImageMagick

suse-cvrf
4 дня назад

Security update for ImageMagick