PT-2017-13611 · Horde+1 · Horde Image+1

Fariskhi Vidyan

+1

·

Publicado

2017-09-21

·

Atualizado

2018-08-18

·

CVE-2017-14650

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Horde Image versions 2.0.0 through 2.5.1
Description A Remote Code Execution issue has been found in the Horde Image library when using the "Im" backend that utilizes ImageMagick's "convert" utility. This issue is not exploitable through any Horde application, as the vulnerable code path is not used by any Horde code. However, custom applications using the Horde Image library might be affected. The problem stems from missing input validation of the index field in raw() during the construction of an ImageMagick command line.
Recommendations For Horde Image versions 2.0.0 through 2.5.1, update to version 2.5.2 to resolve the issue. As a temporary workaround, consider disabling the use of the "Im" backend or restricting access to the raw() function until the update can be applied.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-14650
DLA-1395-1
DSA-4276-1

Produtos afetados

Horde Image
Imagemagick