CVE-2019-12921 — Command Injection in Graphicsmagick
Severity
6.5MEDIUMNVD
EPSS
5.7%
top 9.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 18
Latest updateAug 30
Description
In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6
Affected Packages5 packages
Also affects: Debian Linux 10.0, 8.0, 9.0