Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40929
HistoryJun 16, 2023 - 11:00 a.m.

Command Injection

2023-06-1611:00:13
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
242
imagemagick
command injection
video
vulnerability
system
software
encoding/decoding
attacker
arbitrary codes

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

9.9%

ImageMagick is vulnerable to Command Injection. The vulnerability exists via video:vsync or video:pixel-format options in VIDEO encoding/decoding which allows an attacker to inject and execute arbitrary codes into the system.

CPENameOperatorVersion
imagemagickle6.8.8-9
imagemagickle6.8.8-9

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

9.9%