Skip to main content

ImageMagick Input Validation Vulnerability (ImageTragick)

Last Update Date: 5 May 2016 09:59 Release Date: 5 May 2016 3250 Views

RISK: Extremely High Risk

TYPE: Web services - Web Servers

TYPE: Web Servers

An input validation vulnerability has been identified in ImageMagick, which could be exploited by remoter attacker to execute arbitrary code on target system.

 

The vulnerability could affect web server since a common vulnerable configuration would be a web server that allows image uploads that are subsequently processed with ImageMagick.

 

The vulnerability is also known as "ImageTragick" (https://imagetragick.com/).

 

Note:

  1. Exploit code for this vulnerability is publicly available
  2. The vulnerability is already being exploited in the wild.

Impact

  • Remote Code Execution

System / Technologies affected

  • Versions prior to 6.9.3-10 and 7.0.1-1

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link