ImageMagick CVE-2017-18029 Information Disclosure Vulnerability



ImageMagick is prone to an information-disclosure vulnerability.

An attacker can exploit this issue to gain access to sensitive information that may aid in further attacks. Failed exploit attempts may result in denial-of-service conditions.

ImageMagick 7.0.6-10 Q16 is vulnerable; other versions may also be affected.

Information

Bugtraq ID: 102519
Class: Failure to Handle Exceptional Conditions
CVE: CVE-2017-18029

Remote: Yes
Local: No
Published: Jan 12 2018 12:00AM
Updated: Jan 12 2018 12:00AM
Credit: ADLab of Venustech
Vulnerable: Redhat Enterprise Linux 7
Redhat Enterprise Linux 6
+ Trustix Secure Enterprise Linux 2.0
+ Trustix Secure Linux 2.2
+ Trustix Secure Linux 2.1
+ Trustix Secure Linux 2.0
Redhat Enterprise Linux 5
ImageMagick ImageMagick 7.0.6-10 Q16


Not Vulnerable:

Exploit


The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.


Related Posts

Comments