Bug 4066 - Bugfix for CVE-2022-44268
Summary: Bugfix for CVE-2022-44268
Status: NEW
Alias: None
Product: Anolis OS 7
Classification: Anolis OS
Component: BaseOS Packages (show other bugs) BaseOS Packages
Version: 7.9
Hardware: All Linux
: P3-Medium S2-major
Target Milestone: ---
Assignee: gaochang
QA Contact: 杨晓旋
URL:
Whiteboard:
Keywords:
Depends on:
Blocks: 4067
  Show dependency tree
 
Reported: 2023-02-15 11:49 UTC by Shiloong
Modified: 2023-02-15 11:51 UTC (History)
1 user (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Shiloong admin 2023-02-15 11:49:15 UTC
Description of problem:
An information disclosure vulnerability was found in ImageMagick. This flaw allows an attacker to read arbitrary files from a server when parsing an image and happens when the program is parsing a PNG image. If ImageMagick has permission to read other arbitrary files, the resulting image could have been embedded with contents from another file on the machine after the parsing process.


Version-Release number of selected component (if applicable):
ImageMagick 7.1.0-52, ImageMagick 6.9.12-67


Bugfix:
https://github.com/ImageMagick/ImageMagick6/commit/3c5188b41902a909e163492fb0c19e49efefcefe