CVE-2003-0455Imagemagick vulnerability

6 documents6 sources
Severity
4.6MEDIUMNVD
EPSS
0.1%
top 79.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 7
Latest updateApr 29

Description

The imagemagick libmagick library 5.5 and earlier creates temporary files insecurely, which allows local users to create or overwrite arbitrary files.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages3 packages

debiandebian/imagemagick< imagemagick 4:5.5.7-1 (bookworm)
Debianimagemagick/imagemagick< 4:5.5.7-1+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mjj5-jqj3-25q9: The imagemagick libmagick library 52022-04-29
OSV
CVE-2003-0455: The imagemagick libmagick library 52003-08-07

📋Vendor Advisories

2
Red Hat
security flaw2003-06-28
Debian
CVE-2003-0455: imagemagick - The imagemagick libmagick library 5.5 and earlier creates temporary files insecu...2003

💬Community

1
Bugzilla
CVE-2003-0455 security flaw2018-08-16