Vulnerability Description
ImageMagick is a free and open-source software suite, used for editing and manipulating digital images. The `AppImage` version `ImageMagick` might use an empty path when setting `MAGICK_CONFIGURE_PATH` and `LD_LIBRARY_PATH` environment variables while executing, which might lead to arbitrary code execution by loading malicious configuration files or shared libraries in the current working directory while executing `ImageMagick`. The vulnerability is fixed in 7.11-36.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Imagemagick | Imagemagick | >= 7.0.11-13, < 7.1.1-36 |
| Linux | Linux Kernel | - |
Related Weaknesses (CWE)
References
- https://github.com/ImageMagick/ImageMagick/blob/3b22378a23d59d7517c43b65b1822f02Issue Tracking
- https://github.com/ImageMagick/ImageMagick/commit/6526a2b28510ead6a3e14de711bb99Patch
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8rxc-922v-phExploitVendor Advisory
- https://github.com/ImageMagick/ImageMagick/blob/3b22378a23d59d7517c43b65b1822f02Issue Tracking
- https://github.com/ImageMagick/ImageMagick/commit/6526a2b28510ead6a3e14de711bb99Patch
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8rxc-922v-phExploitVendor Advisory
FAQ
What is CVE-2024-41817?
CVE-2024-41817 is a vulnerability with a CVSS score of 7.0 (HIGH). ImageMagick is a free and open-source software suite, used for editing and manipulating digital images. The `AppImage` version `ImageMagick` might use an empty path when setting `MAGICK_CONFIGURE_PATH...
How severe is CVE-2024-41817?
CVE-2024-41817 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-41817?
Check the references section above for vendor advisories and patch information. Affected products include: Imagemagick Imagemagick, Linux Linux Kernel.