|
|
Info |
Last Modified |
| about 1 year ago |
|
|
|
|
|
Description |
Various ImageMagick utilities fail to correctly validate image file names. The issue is triggered when specially crafted shell commands are part of the file name provided. It is possible that the flaw may allow execution of arbitrary shell commands, resulting in a loss of integrity.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
|
|
Technical |
This vulnerability is only present for ImageMagick utilities which make use of the 'delegate' code and for graphics formats for which 'delegates' are defined, e.g. WMF.
|
|
Solution |
Currently, there are no known upgrades or patches to correct this issue. It is possible to correct the flaw by not using ImageMagick to open suspicious-looking file names.
|
|
Products |
|
ImageMagick
 |
6.2.4.5 |
|
|
|
|
|
|
|
Credit |
- Florian Weimer - fw
deneb.enyo.de -
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|