PT-2020-6203 · Graphicsmagick+4 · Graphicsmagick+4

D4D

·

Published

2020-03-18

·

Updated

2022-08-30

·

CVE-2019-12921

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GraphicsMagick versions prior to 1.3.32
Description The issue is related to information disclosure, allowing remote attackers to read arbitrary files via a crafted image because of the TranslateTextEx function for SVG. This can lead to unauthorized access to confidential data.
Recommendations For versions prior to 1.3.32, update to version 1.3.32 or later to resolve the issue. As a temporary workaround, consider restricting the use of the TranslateTextEx function for SVG until a patch is available.

Exploit

Fix

Command Injection

Information Disclosure

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2894
ALT-PU-2021-1452
BDU:2021-03545
CVE-2019-12921
DLA-2152-1
DSA-4675-1
OPENSUSE-SU-2020:0416-1
OPENSUSE-SU-2020:0429-1
OPENSUSE-SU-2020_0416-1
USN-5190-1

Affected Products

Alt Linux
Graphicsmagick
Linuxmint
Suse
Ubuntu