Bug 4067 - Bugfix for CVE-2022-44268
Summary: Bugfix for CVE-2022-44268
Status: NEW
Alias: None
Product: Anolis OS 8
Classification: Anolis OS
Component: BaseOS Packages (show other bugs) BaseOS Packages
Version: 8.8
Hardware: All Linux
: P3-Medium S2-major
Target Milestone: ---
Assignee: gaochang
QA Contact: shuming
URL:
Whiteboard:
Keywords:
Depends on: 4066
Blocks:
  Show dependency tree
 
Reported: 2023-02-15 11:51 UTC by Shiloong
Modified: 2023-02-15 12:38 UTC (History)
3 users (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Shiloong admin 2023-02-15 11:51:27 UTC
+++ This bug was initially created as a clone of Bug #4066 +++

Description of problem:
An information disclosure vulnerability was found in ImageMagick. This flaw allows an attacker to read arbitrary files from a server when parsing an image and happens when the program is parsing a PNG image. If ImageMagick has permission to read other arbitrary files, the resulting image could have been embedded with contents from another file on the machine after the parsing process.


Version-Release number of selected component (if applicable):
ImageMagick 7.1.0-52, ImageMagick 6.9.12-67


Bugfix:
https://github.com/ImageMagick/ImageMagick6/commit/3c5188b41902a909e163492fb0c19e49efefcefe