CVE-2020-29599
published 2020-12-07CVE-2020-29599: ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which allows setting a password for password-protected PDF files…
PriorityP344high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
7.51%
93.8th percentile
ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which allows setting a password for password-protected PDF files. The user-controlled password was not properly escaped/sanitized and it was therefore possible to inject additional shell commands via coders/pdf.c.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | imagemagick | < imagemagick 8:6.9.11.57+dfsg-1 (bookworm) | imagemagick 8:6.9.11.57+dfsg-1 (bookworm) |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.57+dfsg-1 | 8:6.9.11.57+dfsg-1 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.57+dfsg-1 | 8:6.9.11.57+dfsg-1 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.57+dfsg-1 | 8:6.9.11.57+dfsg-1 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.57+dfsg-1 | 8:6.9.11.57+dfsg-1 |
| imagemagick | imagemagick | >= 0 < 8:6.9.10.23+dfsg-2.1ubuntu11.9 | 8:6.9.10.23+dfsg-2.1ubuntu11.9 |
| imagemagick | imagemagick | >= 0 < 8:6.9.10.23+dfsg-2.1ubuntu11.10 | 8:6.9.10.23+dfsg-2.1ubuntu11.10 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5 | 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5 |
| imagemagick | imagemagick | >= 0 < 8:6.8.9.9-7ubuntu5.16+esm8 | 8:6.8.9.9-7ubuntu5.16+esm8 |
| imagemagick | imagemagick | >= 0 < 8:6.9.7.4+dfsg-16ubuntu6.15+esm1 | 8:6.9.7.4+dfsg-16ubuntu6.15+esm1 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+esm2 | 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+esm2 |
| imagemagick | imagemagick | >= 6.9.8-1 < 6.9.11-40 | 6.9.11-40 |
| imagemagick | imagemagick | >= 7.0.5-3 < 7.0.10-40 | 7.0.10-40 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor ImageMagick invocations where the -authenticate option is supplied with values containing shell metacharacters (e.g. ;, |, $(), backticks), as the password value is passed unsanitized into a shell command in coders/pdf.c ↗
- →Flag any ImageMagick process invocation that includes both a PDF file argument and the -authenticate flag, especially when the password argument contains shell special characters ↗
- →Vulnerable versions are ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40; alert on process execution of these versions processing PDF files with -authenticate ↗
- ·Inkscape bundles ImageMagick as a dependency but is NOT affected because its primary usage of ImageMagick is for bitmap filters, which does not expose the vulnerable code path in coders/pdf.c ↗
- ·The vulnerability is only exploitable when ImageMagick is used to process password-protected PDF files with the -authenticate option exposed to user-controlled input; deployments that do not process PDFs or do not expose -authenticate to user input are not at risk ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2024-07-25·CVSS 7.8
CVE-2023-1289 [HIGH] ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: Several security issues were fixed in ImageMagick.
USN-6200-1 fixed vulnerabilities in ImageMagick. Unfortunately these fixes were
incomplete for Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. This update fixes the
problem.
Original advisory details:
It was discovered that ImageMagick incorrectly handled the "-authenticate"
option for password-protected PDF files. An attacker could possibly use
this issue to inject additional shell commands and perform arbitrary code
execution. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-29599)
It was discovered that ImageMagick incorrectly handled certain values
when processing PDF files. If a user or automated system using ImageMagick
were tricked into opening a specially crafted PDF file, an attacker co
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2023-07-04·CVSS 7.8
CVE-2023-1289 [HIGH] ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: Several security issues were fixed in ImageMagick.
It was discovered that ImageMagick incorrectly handled the "-authenticate"
option for password-protected PDF files. An attacker could possibly use
this issue to inject additional shell commands and perform arbitrary code
execution. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-29599)
It was discovered that ImageMagick incorrectly handled certain values
when processing PDF files. If a user or automated system using ImageMagick
were tricked into opening a specially crafted PDF file, an attacker could
exploit this to cause a denial of service. This issue only affected Ubuntu
20.04 LTS. (CVE-2021-20224)
Zhang Xiaohui discovered that ImageMagick incorrectly handled certain
values when proce
Red Hat
ImageMagick: Shell injection via PDF password could result in arbitrary code execution
vendor_redhat·2020-12-07·CVSS 7.8
CVE-2020-29599 [HIGH] CWE-77 ImageMagick: Shell injection via PDF password could result in arbitrary code execution
ImageMagick: Shell injection via PDF password could result in arbitrary code execution
ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which allows setting a password for password-protected PDF files. The user-controlled password was not properly escaped/sanitized and it was therefore possible to inject additional shell commands via coders/pdf.c.
A flaw was found in ImageMagick. The -authenticate option is mishandled allowing user-controlled password set for a PDF file to possibly inject additional shell commands via coders/pdf.c. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: Although ImageMagick is shipped as bundled dependency of Inkscape, the further package is
Debian
CVE-2020-29599: imagemagick - ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authentica...
vendor_debian·2020·CVSS 7.8
CVE-2020-29599 [HIGH] CVE-2020-29599: imagemagick - ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authentica...
ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which allows setting a password for password-protected PDF files. The user-controlled password was not properly escaped/sanitized and it was therefore possible to inject additional shell commands via coders/pdf.c.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.57+dfsg-1)
bullseye: resolved (fixed in 8:6.9.11.57+dfsg-1)
forky: resolved (fixed in 8:6.9.11.57+dfsg-1)
sid: resolved (fixed in 8:6.9.11.57+dfsg-1)
trixie: resolved (fixed in 8:6.9.11.57+dfsg-1)
OSV
imagemagick vulnerabilities
osv·2024-07-25·CVSS 7.8
[HIGH] imagemagick vulnerabilities
imagemagick vulnerabilities
USN-6200-1 fixed vulnerabilities in ImageMagick. Unfortunately these fixes were
incomplete for Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. This update fixes the
problem.
Original advisory details:
It was discovered that ImageMagick incorrectly handled the "-authenticate"
option for password-protected PDF files. An attacker could possibly use
this issue to inject additional shell commands and perform arbitrary code
execution. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-29599)
It was discovered that ImageMagick incorrectly handled certain values
when processing PDF files. If a user or automated system using ImageMagick
were tricked into opening a specially crafted PDF file, an attacker could
exploit this to cause a denial of service. This issue only affec
OSV
imagemagick vulnerabilities
osv·2023-07-04·CVSS 7.8
CVE-2020-29599 [HIGH] imagemagick vulnerabilities
imagemagick vulnerabilities
It was discovered that ImageMagick incorrectly handled the "-authenticate"
option for password-protected PDF files. An attacker could possibly use
this issue to inject additional shell commands and perform arbitrary code
execution. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-29599)
It was discovered that ImageMagick incorrectly handled certain values
when processing PDF files. If a user or automated system using ImageMagick
were tricked into opening a specially crafted PDF file, an attacker could
exploit this to cause a denial of service. This issue only affected Ubuntu
20.04 LTS. (CVE-2021-20224)
Zhang Xiaohui discovered that ImageMagick incorrectly handled certain
values when processing image data. If a user or automated system using
ImageMagick we
GHSA
GHSA-685x-r4m9-ffxr: ImageMagick before 6
ghsa_unreviewed·2022-05-24
CVE-2020-29599 [HIGH] CWE-91 GHSA-685x-r4m9-ffxr: ImageMagick before 6
ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which allows setting a password for password-protected PDF files. The user-controlled password was not properly escaped/sanitized and it was therefore possible to inject additional shell commands via coders/pdf.c.
OSV
CVE-2020-29599: ImageMagick before 6
osv·2020-12-07·CVSS 7.8
CVE-2020-29599 [HIGH] CVE-2020-29599: ImageMagick before 6
ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which allows setting a password for password-protected PDF files. The user-controlled password was not properly escaped/sanitized and it was therefore possible to inject additional shell commands via coders/pdf.c.
No detection rules found.
No public exploits indexed.
https://github.com/ImageMagick/ImageMagick/discussions/2851https://insert-script.blogspot.com/2020/11/imagemagick-shell-injection-via-pdf.htmlhttps://lists.debian.org/debian-lts-announce/2021/01/msg00010.htmlhttps://lists.debian.org/debian-lts-announce/2023/03/msg00008.htmlhttps://security.gentoo.org/glsa/202101-36https://github.com/ImageMagick/ImageMagick/discussions/2851https://insert-script.blogspot.com/2020/11/imagemagick-shell-injection-via-pdf.htmlhttps://lists.debian.org/debian-lts-announce/2021/01/msg00010.htmlhttps://lists.debian.org/debian-lts-announce/2023/03/msg00008.htmlhttps://security.gentoo.org/glsa/202101-36
2020-12-07
Published