Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-44268


ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded the content of an arbitrary. file (if the magick binary has permissions to read it).


Published

2023-02-06T21:15:09.473

Last Modified

2025-03-26T15:15:40.750

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application imagemagick imagemagick 7.1.0-49 Yes

References