CVE-2019-12921Command Injection in Graphicsmagick

Severity
6.5MEDIUMNVD
EPSS
5.7%
top 9.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 18
Latest updateAug 30

Description

In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

Debiangraphicsmagick/graphicsmagick< 1.4~hg16039-1+3
Ubuntugraphicsmagick/graphicsmagick< 1.3.18-1ubuntu3.1+esm7+3
NVDopensuse/leap15.1

Also affects: Debian Linux 10.0, 8.0, 9.0

🔴Vulnerability Details

4
OSV
graphicsmagick vulnerabilities2022-08-30
GHSA
GHSA-5vwc-wxpp-mxp8: In GraphicsMagick before 12022-05-24
CVEList
CVE-2019-12921: In GraphicsMagick before 12020-03-18
OSV
CVE-2019-12921: In GraphicsMagick before 12020-03-18

📋Vendor Advisories

2
Ubuntu
GraphicsMagick vulnerabilities2022-08-30
Debian
CVE-2019-12921: graphicsmagick - In GraphicsMagick before 1.3.32, the text filename component allows remote attac...2019

📐Framework References

1
CWE
Improper Neutralization of Special Elements used in a Command ('Command Injection')

💬Community

3
Bugzilla
CVE-2019-12921 GraphicsMagick: arbitrary file read via crafted image2020-06-29
Bugzilla
CVE-2019-12921 GraphicsMagick: arbitrary file read via crafted image [fedora-all]2020-06-29
Bugzilla
CVE-2019-12921 GraphicsMagick: arbitrary file read via crafted image [epel-all]2020-06-29
CVE-2019-12921 — Command Injection in Graphicsmagick | cvebase