CVE-2023-34152

SOURCE - nist

Summary

A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.

EPSS Score: 0.00386 (0.731)

Common Weakness Enumeration (CWE)

SOURCE - nist

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

SOURCE - redhat

Improper Input Validation


debian

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow
PackageTypeOS NameOS VersionAffected RangesFix Versions
debian/imagemagickdebdebian12>=8:6.9.11.60+dfsg-1.6Not yet available
debian/imagemagickdebdebian13>=8:6.9.12.98+dfsg1-5.2Not yet available
debian/imagemagickdebdebianunstable>=8:6.9.12.98+dfsg1-5.2Not yet available
debian/imagemagickdebdebian10>=8:6.9.10.23+dfsg-2.1+deb10u1Not yet available
debian/imagemagickdebdebian11>=8:6.9.11.60+dfsg-1.3+deb11u2Not yet available

Severity and metrics

No CVSS data available from this source.

nist

CREATED


UPDATED



EXPLOITABILITY SCORE

3.9


EXPLOITS FOUND

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

9.8critical

ubuntu

CREATED


UPDATED



EXPLOITABILITY SCORE

3.9


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

9.8medium

redhat

CREATED


UPDATED



EXPLOITABILITY SCORE

3.9


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

9.4high

inthewild

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND

-


COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM SOURCE