[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-5347-1 imagemagick -- imagemagick

ID: oval:org.secpod.oval:def:89348Date: (C)2023-11-28   (M)2024-01-29
Class: PATCHFamily: unix




Bryan Gonzalez discovered that the PNG support in Imagemagick could be tricked into embedding the content of an arbitrary file when converting an image file.

Platform:
Linux Mint 5
Product:
libmagick++-6.q16hdri-dev
libmagick++-6.q16hdri-8
imagemagick
libmagickwand-6.q16hdri-dev
libmagickwand-6.q16-dev
libmagickcore-6.q16-6
libmagickwand-dev
libmagickcore-6-headers
libmagickcore-6.q16hdri-dev
libmagick++-dev
libmagick++-6.q16-dev
libmagickwand-6.q16-6
libmagickcore-6.q16-dev
perlmagick
libmagickwand-6-headers
libmagick++-6-headers
libimage-magick-q16-perl
libimage-magick-perl
libmagickcore-6.q16hdri-6
libimage-magick-q16hdri-perl
libmagickcore-6-arch-config
libmagickcore-dev
libmagick++-6.q16-8
libmagickwand-6.q16hdri-6
Reference:
DSA-5347-1
CVE-2022-44267
CVE-2022-44268
CVE    2
CVE-2022-44267
CVE-2022-44268
CPE    19
cpe:/a:imagemagick:libmagickcore-6.q16-6
cpe:/a:imagemagick:libmagickwand-6.q16hdri-6
cpe:/a:imagemagick:imagemagick
cpe:/a:imagemagick:libmagickcore-6.q16hdri-6
...

© SecPod Technologies