Описание
ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlink between policy validation (check-time) and the file write operation (use-time) to write to policy-denied locations.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| imagemagick | fixed | 8:7.1.2.31+dfsg1-1 | package | |
| imagemagick | no-dsa | trixie | package |
Примечания
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9x6f-98x9-rx6g
Fixed by: https://github.com/ImageMagick/ImageMagick/commit/a44ef50cc494253f7d9f0229bb25c064a8e2ae69 (7.1.2-30)
Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/0b47fb7e3d5650b2be88fd3a8c15096765970ce3 (6.9.13-55)
EPSS
Связанные уязвимости
(ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-tim ...)
ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlink between policy validation (check-time) and the file write operation (use-time) to write to policy-denied locations.
ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlink between policy validation (check-time) and the file write operation (use-time) to write to policy-denied locations.
ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlink between policy validation (check-time) and the file write operation (use-time) to write to policy-denied locations.
EPSS