Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-44268
HistoryFeb 06, 2023 - 12:00 a.m.

CVE-2022-44268

2023-02-0600:00:00
ubuntu.com
ubuntu.com
60
imagemagick
information disclosure
png
image parsing
ubuntu
file content
permissions
bug tracking

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

0.014 Low

EPSS

Percentile

86.6%

ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it
parses a PNG image (e.g., for resize), the resulting image could have
embedded the content of an arbitrary. file (if the magick binary has
permissions to read it).

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchimagemagick< 8:6.9.7.4+dfsg-16ubuntu6.15UNKNOWN
ubuntu20.04noarchimagemagick< 8:6.9.10.23+dfsg-2.1ubuntu11.5UNKNOWN
ubuntu22.04noarchimagemagick< 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.1UNKNOWN
ubuntu22.10noarchimagemagick< 8:6.9.11.60+dfsg-1.3ubuntu0.22.10.2UNKNOWN
ubuntu23.10noarchimagemagick< anyUNKNOWN
ubuntu24.04noarchimagemagick< anyUNKNOWN
ubuntu14.04noarchimagemagick< 8:6.7.7.10-6ubuntu3.13+esm5UNKNOWN
ubuntu16.04noarchimagemagick< 8:6.8.9.9-7ubuntu5.16+esm7UNKNOWN

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

0.014 Low

EPSS

Percentile

86.6%