Lucene search

K
f5F5F5:K000132457
HistoryFeb 08, 2023 - 12:00 a.m.

K000132457 : ImageMagick vulnerability CVE-2022-44268

2023-02-0800:00:00
my.f5.com
5
imagemagick
information disclosure
png
big-ip
aam
edge gateway
webaccelerator
vulnerability
cve-2022-44268
f5
big-iq centralized management
nginx
traffix sdc

6.3 Medium

AI Score

Confidence

Low

0.014 Low

EPSS

Percentile

86.6%

Security Advisory Description

ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded the content of an arbitrary. file (if the magick binary has permissions to read it). (CVE-2022-44268)

Impact

BIG-IP (AAM, Edge Gateway, and WebAccelerator)

This issue affects BIG-IP systems only when WAM or AAM is provisioned. If exploited, this vulnerability may result in an information leak.

BIG-IP (LTM, AFM, Analytics, APM, ASM, DNS, FPS, GTM, Link Controller, PEM), BIG-IQ Centralized Management, SPK, NGINX, and Traffix SDC

There is no impact; these F5 products are not affected by this vulnerability.