Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-61858

Опубликовано: 11 июл. 2026
Источник: redhat
CVSS3: 3.3

Описание

ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process.

A flaw was found in ImageMagick. This vulnerability allows attackers to bypass configured policy restrictions through the APNG (Animated Portable Network Graphics) encoding process. By exploiting missing validation checks in the APNG encoder and external delegates, an attacker can write files to disallowed paths. This could lead to unauthorized file creation or modification, potentially impacting system integrity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2499370ImageMagick: ImageMagick: Policy bypass allows unauthorized file writing via APNG encoder

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
20 дней назад

ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process.

CVSS3: 3.3
nvd
20 дней назад

ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process.

CVSS3: 3.3
debian
20 дней назад

ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in ...

CVSS3: 3.3
github
20 дней назад

ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process.

suse-cvrf
12 дней назад

Security update for ImageMagick

3.3 Low

CVSS3