Do your applications use this vulnerable package?
Test your applications
Overview
Affected versions of this package are vulnerable to XML Injection. ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which allows setting a password for password-protected PDF files. The user-controlled password was not properly escaped/sanitized and it was therefore possible to inject additional shell commands via coders/pdf.c.
Remediation
There is no fixed version for imagemagick
.
References
CVSS Score
7.8
high severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionRequired
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityHigh
- CVE
- CVE-2020-29599
- CWE
- CWE-91
- Snyk ID
- SNYK-DEBIAN10-IMAGEMAGICK-1049976
- Disclosed
- 07 Dec, 2020
- Published
- 10 Dec, 2020