It was discovered that certain ImageMagick coders and pseudo-protocols did not properly prevent security sensitive operations when processing specially crafted images. A remote attacker could create a specially crafted image that, when processed by an application using ImageMagick or an unsuspecting user using the ImageMagick utilities, would allow the attacker to disclose the contents of arbitrary files.
Platform | Package | Release Date | Advisory |
---|---|---|---|
Amazon Linux 1 | ImageMagick | 2016-05-11 11:00 | ALAS-2016-699 |
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv2 | 7.1 | AV:N/AC:M/Au:N/C:C/I:N/A:N |
NVD | CVSSv2 | 7.1 | AV:N/AC:M/Au:N/C:C/I:N/A:N |
NVD | CVSSv3 | 5.5 | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |