Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3392
HistoryFeb 01, 2017 - 8:53 a.m.

Remote Code Execution (RCE)

2017-02-0108:53:07
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.967 High

EPSS

Percentile

99.7%

ImageMagick is vulnerable to remote code execution (RCE). The library does not sanitize certain user inputs, allowing a malicious user to pass a malicious image to the system for file conversion to trigger the execution of arbitrary code. This is also known as the ImageTragick vulnerability.

CPENameOperatorVersion
imagemagickle6.8.8-9
imagemagickle6.8.8-9

References