ZeroHour

CVE-2022-44268

PoC
CVSS 3.1
6.5 medium
EPSS
90%p100
Published
()
Modified
Description

ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded the content of an arbitrary. file (if the magick binary has permissions to read it).

Vendors
imagemagick
Products
imagemagick
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news