PT-2026-60152 · Unknown · Imagemagick
CVSS v3.1
2.9
Low
| Vector | AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ImageMagick versions prior to 7.1.2-26
ImageMagick versions prior to 6.9.13-51
Description
An information disclosure issue exists when using the
identify command to display a profile. If the profile value is not printable and debug output is enabled, the system may read past the profile boundary and print a single byte from the end of the profile.Recommendations
Update ImageMagick to version 7.1.2-26 or later.
Update ImageMagick to version 6.9.13-51 or later.
Disable debug output to prevent the disclosure of memory bytes.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Imagemagick