Required CVE Record Information
Description
ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which allows setting a password for password-protected PDF files. The user-controlled password was not properly escaped/sanitized and it was therefore possible to inject additional shell commands via coders/pdf.c.
References 5 Total
- https://insert-script.blogspot.com/2020/11/imagemagick-shell-injection-via-pdf.html
- https://github.com/ImageMagick/ImageMagick/discussions/2851
- lists.debian.org: [debian-lts-announce] 20210112 [SECURITY] [DLA 2523-1] imagemagick security update mailing-list
- security.gentoo.org: GLSA-202101-36 vendor-advisory
- lists.debian.org: [debian-lts-announce] 20230311 [SECURITY] [DLA 3357-1] imagemagick security update mailing-list
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 5 Total
- https://insert-script.blogspot.com/2020/11/imagemagick-shell-injection-via-pdf.html x_transferred
- https://github.com/ImageMagick/ImageMagick/discussions/2851 x_transferred
- lists.debian.org: [debian-lts-announce] 20210112 [SECURITY] [DLA 2523-1] imagemagick security update mailing-listx_transferred
- security.gentoo.org: GLSA-202101-36 vendor-advisoryx_transferred
- lists.debian.org: [debian-lts-announce] 20230311 [SECURITY] [DLA 3357-1] imagemagick security update mailing-listx_transferred