CVE-2005-3582Imagemagick vulnerability

4 documents4 sources
Severity
7.2HIGHNVD
EPSS
0.1%
top 82.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 16
Latest updateMay 1

Description

ImageMagick before 6.2.4.2-r1 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages2 packages

NVDimagemagick/imagemagick58 versions+57

Patches

🔴Vulnerability Details

1
GHSA
GHSA-759j-wf5g-3hcr: ImageMagick before 62022-05-01

📋Vendor Advisories

2
Debian
CVE-2005-3582: imagemagick - ImageMagick before 6.2.4.2-r1 allows local users in the portage group to increas...2005
Red Hat
CVE-2005-3582: ImageMagick before 6