摘要:
ImageMagick is a free and open-source software suite, used for editing and manipulating digital images. The `AppImage` version `ImageMagick` might use an empty path when setting `MAGICK_CONFIGURE_PATH` and `LD_LIBRARY_PATH` environment variables while executing, which might lead to arbitrary code execution by loading malicious configuration files or shared libraries in the current working directory while executing `ImageMagick`. The vulnerability is fixed in 7.11-36.
安全等级: Low
公告ID: KylinSec-SA-2024-3253
发布日期: 2024年7月30日
关联CVE: CVE-2024-41817
ImageMagick is a free and open-source software suite, used for editing and manipulating digital images. The `AppImage` version `ImageMagick` might use an empty path when setting `MAGICK_CONFIGURE_PATH` and `LD_LIBRARY_PATH` environment variables while executing, which might lead to arbitrary code execution by loading malicious configuration files or shared libraries in the current working directory while executing `ImageMagick`. The vulnerability is fixed in 7.11-36.
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2024-41817 | KY3.4-5 | ImageMagick | Unaffected |
CVE-2024-41817 | KY3.5.2 | ImageMagick | Unaffected |
CVE-2024-41817 | V6 | ImageMagick | Unaffected |