Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-46693

Опубликовано: 10 июн. 2026
Источник: redhat
CVSS3: 4.4

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to a magick -distribute-cache service can hijack a file descriptor in the server process when a race condition is met. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.

A flaw was found in ImageMagick. An attacker able to connect to a magick -distribute-cache service could exploit a race condition to hijack a file descriptor in the server process. This could lead to unauthorized access to sensitive information.

Отчет

This flaw is rated as Low impact. It requires an attacker to have high privileges and the ability to connect to a magick -distribute-cache service. Exploitation is further limited by the high attack complexity and a race condition, making it difficult to reliably hijack a file descriptor for information disclosure. This service is not typically enabled or exposed by default in Red Hat products.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-910
https://bugzilla.redhat.com/show_bug.cgi?id=2487754ImageMagick: Magick.NET: ImageMagick: Information disclosure via file descriptor hijacking due to a race condition.

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.1
ubuntu
около 2 месяцев назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to a magick -distribute-cache service can hijack a file descriptor in the server process when a race condition is met. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.

CVSS3: 4.1
nvd
около 2 месяцев назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to a magick -distribute-cache service can hijack a file descriptor in the server process when a race condition is met. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.

CVSS3: 4.1
debian
около 2 месяцев назад

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 4.1
github
2 месяца назад

ImageMagick: Race Condition in distributed pixel cache server can result in file descriptor hijacking

CVSS3: 4.1
fstec
около 2 месяцев назад

Уязвимость службы magick-distribute-cache консольного графического редактора ImageMagick, позволяющая нарушителю раскрыть защищаемую информацию

4.4 Medium

CVSS3