CVE Vulnerabilities

CVE-2021-20313

Published: May 11, 2021 | Modified: May 22, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
5.1 LOW
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Ubuntu
LOW

A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in TransformSignature is possible. The highest threat from this vulnerability is to data confidentiality.

Affected Software

Name Vendor Start Version End Version
Imagemagick Imagemagick * 7.0.11-0 (excluding)
Imagemagick Ubuntu bionic *
Imagemagick Ubuntu devel *
Imagemagick Ubuntu esm-apps/jammy *
Imagemagick Ubuntu esm-infra/xenial *
Imagemagick Ubuntu focal *
Imagemagick Ubuntu groovy *
Imagemagick Ubuntu hirsute *
Imagemagick Ubuntu impish *
Imagemagick Ubuntu jammy *
Imagemagick Ubuntu kinetic *
Imagemagick Ubuntu lunar *
Imagemagick Ubuntu mantic *
Imagemagick Ubuntu noble *
Imagemagick Ubuntu oracular *
Imagemagick Ubuntu trusty *
Imagemagick Ubuntu trusty/esm *
Imagemagick Ubuntu xenial *

References