Описание
In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support, was needed |
| devel | not-affected | 1.4+really1.3.38-1 |
| eoan | not-affected | 1.4+really1.3.33+hg16115-1 |
| esm-apps/bionic | released | 1.3.28-2ubuntu0.1+esm1 |
| esm-apps/focal | not-affected | 1.4+really1.3.35-1 |
| esm-apps/jammy | not-affected | 1.4+really1.3.38-1 |
| esm-apps/xenial | released | 1.3.23-1ubuntu0.6+esm1 |
| esm-infra-legacy/trusty | released | 1.3.18-1ubuntu3.1+esm7 |
| focal | not-affected | 1.4+really1.3.35-1 |
| groovy | ignored | end of life |
Показывать по
EPSS
4.3 Medium
CVSS2
6.5 Medium
CVSS3
Связанные уязвимости
In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG.
In GraphicsMagick before 1.3.32, the text filename component allows re ...
In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG.
Уязвимость набора приложений командной строки для обработки файлов изображений GraphicsMagick, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным
EPSS
4.3 Medium
CVSS2
6.5 Medium
CVSS3