Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-41817

Опубликовано: 27 июл. 2024
Источник: redhat
CVSS3: 7.3
EPSS Средний

Описание

ImageMagick is a free and open-source software suite, used for editing and manipulating digital images. The AppImage version ImageMagick might use an empty path when setting MAGICK_CONFIGURE_PATH and LD_LIBRARY_PATH environment variables while executing, which might lead to arbitrary code execution by loading malicious configuration files or shared libraries in the current working directory while executing ImageMagick. The vulnerability is fixed in 7.11-36.

A flaw was found in ImageMagick. The 'AppImage' version of ImageMagick, when executed with an empty path in the MAGICK_CONFIGURE_PATH and LD_LIBRARY_PATH environment variables, can load malicious configuration files or shared libraries in the current directory, resulting in arbitrary code execution.

Отчет

ImageMagick as shipped in Red Hat Enterprise Linux is not affected by this vulnerability because the vulnerable code is not present. Additionally, this issue only affects the 'AppImage' version of ImageMagick, which is not shipped in any Red Hat product.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickNot affected
Red Hat Enterprise Linux 7ImageMagickNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-427
https://bugzilla.redhat.com/show_bug.cgi?id=2300498ImageMagick: Possible arbitrary code execution by loading malicious configuration files or shared libraries

EPSS

Процентиль: 95%
0.19061
Средний

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
больше 1 года назад

ImageMagick is a free and open-source software suite, used for editing and manipulating digital images. The `AppImage` version `ImageMagick` might use an empty path when setting `MAGICK_CONFIGURE_PATH` and `LD_LIBRARY_PATH` environment variables while executing, which might lead to arbitrary code execution by loading malicious configuration files or shared libraries in the current working directory while executing `ImageMagick`. The vulnerability is fixed in 7.11-36.

CVSS3: 7
nvd
больше 1 года назад

ImageMagick is a free and open-source software suite, used for editing and manipulating digital images. The `AppImage` version `ImageMagick` might use an empty path when setting `MAGICK_CONFIGURE_PATH` and `LD_LIBRARY_PATH` environment variables while executing, which might lead to arbitrary code execution by loading malicious configuration files or shared libraries in the current working directory while executing `ImageMagick`. The vulnerability is fixed in 7.11-36.

CVSS3: 7
debian
больше 1 года назад

ImageMagick is a free and open-source software suite, used for editing ...

EPSS

Процентиль: 95%
0.19061
Средний

7.3 High

CVSS3