CVE Vulnerabilities

CVE-2022-44268

Published: Feb 06, 2023 | Modified: Mar 26, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded the content of an arbitrary. file (if the magick binary has permissions to read it).

Affected Software

NameVendorStart VersionEnd Version
ImagemagickImagemagick7.1.0-49 (including)7.1.0-49 (including)
ImagemagickUbuntubionic*
ImagemagickUbuntuesm-apps/focal*
ImagemagickUbuntuesm-apps/jammy*
ImagemagickUbuntuesm-infra-legacy/trusty*
ImagemagickUbuntuesm-infra/bionic*
ImagemagickUbuntuesm-infra/xenial*
ImagemagickUbuntufocal*
ImagemagickUbuntujammy*
ImagemagickUbuntukinetic*
ImagemagickUbuntulunar*
ImagemagickUbuntumantic*
ImagemagickUbuntutrusty*
ImagemagickUbuntutrusty/esm*
ImagemagickUbuntuxenial*

References