PT-2021-7869 · Unknown+4 · Imagemagick+4
Lemstrap
·
Published
2021-09-11
·
Updated
2023-07-04
·
CVE-2021-39212
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ImageMagick versions prior to 6.9.12-22
ImageMagick versions prior to 7.1.0-7
Description
The issue is related to the handling of Postscript files in ImageMagick, where these files could be read and written even when excluded by a
module policy in policy.xml. This could potentially allow an attacker to access confidential data and compromise its integrity. Fortunately, few users utilize the module policy, and instead, use the coder policy.Recommendations
For versions prior to 6.9.12-22, update to version 6.9.12-22 or later.
For versions prior to 7.1.0-7, update to version 7.1.0-7 or later.
As a temporary workaround, consider using the
coder policy: .Fix
Race Condition
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Imagemagick
Linuxmint
Ubuntu