CVE-2022-44268 EXPLOIT
6.5
MEDIUM · CVSS 3.1 · EPSS 89.9% (pctl 100)
Patch early
A public exploit exists.
Description
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded the content of an arbitrary. file (if the magick binary has permissions to read it).
Scoring
| CVSS | 6.5 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
| EPSS | 89.86% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-200 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2023-02-06 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| imagemagick | imagemagick |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | ImageMagick 7.1.0-49 - Arbitrary File Read | 2023-04-05 |
References
- http://packetstormsecurity.com/files/171727/ImageMagick-7.1.0-48-Arbitrary-File-Read.html
- https://imagemagick.org/
- https://lists.debian.org/debian-lts-announce/2023/03/msg00008.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AINSUL2QBKETGYRPA7XSCMJWLUB44M6S/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZZLLS37P67CMBRML6OCG42GPCKGRCJNV/
- https://www.debian.org/security/2023/dsa-5347
- https://www.metabaseq.com/imagemagick-zero-days/
- http://packetstormsecurity.com/files/171727/ImageMagick-7.1.0-48-Arbitrary-File-Read.html
- https://imagemagick.org/
- https://lists.debian.org/debian-lts-announce/2023/03/msg00008.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AINSUL2QBKETGYRPA7XSCMJWLUB44M6S/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZZLLS37P67CMBRML6OCG42GPCKGRCJNV/
- https://www.debian.org/security/2023/dsa-5347
- https://www.metabaseq.com/imagemagick-zero-days/
→ the Explorer · watch your stack · NVD