Описание
ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink race conditions. Attackers can swap symlinks between policy validation and file access to read or write policy-denied files.
A flaw was found in ImageMagick. This vulnerability, known as a time-of-check-time-of-use (TOCTOU) flaw, affects path policy enforcement on Windows. A local attacker can exploit this by manipulating symbolic links (symlinks) during the brief interval between when the system checks a file's permissions and when it actually accesses the file. This allows the attacker to bypass security restrictions and potentially read or write files that should be protected by policy, leading to unauthorized information disclosure or data modification.
Отчет
Red Hat has evaluated this issue and determined that Red Hat products are not affected. This vulnerability only applies to Windows platforms.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | ImageMagick | Not affected | ||
| Red Hat Enterprise Linux 7 | ImageMagick | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
3.3 Low
CVSS3
Связанные уязвимости
(ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulne ...)
ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink race conditions. Attackers can swap symlinks between policy validation and file access to read or write policy-denied files.
ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulne ...
ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink race conditions. Attackers can swap symlinks between policy validation and file access to read or write policy-denied files.
EPSS
3.3 Low
CVSS3