cbcvebase.
CVE-2020-29599
published 2020-12-07

CVE-2020-29599: ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which allows setting a password for password-protected PDF files…

PriorityP344high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
7.51%
93.8th percentile
ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which allows setting a password for password-protected PDF files. The user-controlled password was not properly escaped/sanitized and it was therefore possible to inject additional shell commands via coders/pdf.c.

Affected

14 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianimagemagick< imagemagick 8:6.9.11.57+dfsg-1 (bookworm)imagemagick 8:6.9.11.57+dfsg-1 (bookworm)
imagemagickimagemagick>= 0 < 8:6.9.11.57+dfsg-18:6.9.11.57+dfsg-1
imagemagickimagemagick>= 0 < 8:6.9.11.57+dfsg-18:6.9.11.57+dfsg-1
imagemagickimagemagick>= 0 < 8:6.9.11.57+dfsg-18:6.9.11.57+dfsg-1
imagemagickimagemagick>= 0 < 8:6.9.11.57+dfsg-18:6.9.11.57+dfsg-1
imagemagickimagemagick>= 0 < 8:6.9.10.23+dfsg-2.1ubuntu11.98:6.9.10.23+dfsg-2.1ubuntu11.9
imagemagickimagemagick>= 0 < 8:6.9.10.23+dfsg-2.1ubuntu11.108:6.9.10.23+dfsg-2.1ubuntu11.10
imagemagickimagemagick>= 0 < 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.58:6.9.11.60+dfsg-1.3ubuntu0.22.04.5
imagemagickimagemagick>= 0 < 8:6.8.9.9-7ubuntu5.16+esm88:6.8.9.9-7ubuntu5.16+esm8
imagemagickimagemagick>= 0 < 8:6.9.7.4+dfsg-16ubuntu6.15+esm18:6.9.7.4+dfsg-16ubuntu6.15+esm1
imagemagickimagemagick>= 0 < 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+esm28:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+esm2
imagemagickimagemagick>= 6.9.8-1 < 6.9.11-406.9.11-40
imagemagickimagemagick>= 7.0.5-3 < 7.0.10-407.0.10-40

Detection & IOCsextracted from sources · hover to see the quote

pathcoders/pdf.c
command-authenticate
  • Monitor ImageMagick invocations where the -authenticate option is supplied with values containing shell metacharacters (e.g. ;, |, $(), backticks), as the password value is passed unsanitized into a shell command in coders/pdf.c
  • Flag any ImageMagick process invocation that includes both a PDF file argument and the -authenticate flag, especially when the password argument contains shell special characters
  • Vulnerable versions are ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40; alert on process execution of these versions processing PDF files with -authenticate
  • ·Inkscape bundles ImageMagick as a dependency but is NOT affected because its primary usage of ImageMagick is for bitmap filters, which does not expose the vulnerable code path in coders/pdf.c
  • ·The vulnerability is only exploitable when ImageMagick is used to process password-protected PDF files with the -authenticate option exposed to user-controlled input; deployments that do not process PDFs or do not expose -authenticate to user input are not at risk

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.