CVE-2021-20313
published 2021-05-11CVE-2021-20313: A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in TransformSignature is possible. The highest…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.78%
76.0th percentile
A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in TransformSignature is possible. The highest threat from this vulnerability is to data confidentiality.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | imagemagick | < imagemagick 8:6.9.11.60+dfsg-1.5 (bookworm) | imagemagick 8:6.9.11.60+dfsg-1.5 (bookworm) |
| imagemagick | imagemagick | < 7.0.11-0 | 7.0.11-0 |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.3+deb11u4 | 8:6.9.11.60+dfsg-1.3+deb11u4 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.5 | 8:6.9.11.60+dfsg-1.5 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.5 | 8:6.9.11.60+dfsg-1.5 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.5 | 8:6.9.11.60+dfsg-1.5 |
| imagemagick | imagemagick | >= 0 < 8:6.9.7.4+dfsg-16ubuntu6.12 | 8:6.9.7.4+dfsg-16ubuntu6.12 |
| imagemagick | imagemagick | >= 0 < 8:6.9.7.4+dfsg-16ubuntu6.14 | 8:6.9.7.4+dfsg-16ubuntu6.14 |
| imagemagick | imagemagick | >= 0 < 8:6.9.10.23+dfsg-2.1ubuntu11.9 | 8:6.9.10.23+dfsg-2.1ubuntu11.9 |
| imagemagick | imagemagick | >= 0 < 8:6.9.10.23+dfsg-2.1ubuntu11.10 | 8:6.9.10.23+dfsg-2.1ubuntu11.10 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5 | 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5 |
| imagemagick | imagemagick | >= 0 < 8:6.7.7.10-6ubuntu3.13+esm1 | 8:6.7.7.10-6ubuntu3.13+esm1 |
| imagemagick | imagemagick | >= 0 < 8:6.7.7.10-6ubuntu3.13+esm3 | 8:6.7.7.10-6ubuntu3.13+esm3 |
| imagemagick | imagemagick | >= 0 < 8:6.8.9.9-7ubuntu5.16+esm1 | 8:6.8.9.9-7ubuntu5.16+esm1 |
| imagemagick | imagemagick | >= 0 < 8:6.8.9.9-7ubuntu5.16+esm8 | 8:6.8.9.9-7ubuntu5.16+esm8 |
| imagemagick | imagemagick | >= 0 < 8:6.8.9.9-7ubuntu5.16+esm5 | 8:6.8.9.9-7ubuntu5.16+esm5 |
| imagemagick | imagemagick | >= 0 < 8:6.9.7.4+dfsg-16ubuntu6.15+esm1 | 8:6.9.7.4+dfsg-16ubuntu6.15+esm1 |
| imagemagick | imagemagick | >= 0 < 8:6.9.10.23+dfsg-2.1ubuntu11.4+esm1 | 8:6.9.10.23+dfsg-2.1ubuntu11.4+esm1 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.1+esm1 | 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.1+esm1 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+esm2 | 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+esm2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2024-07-25·CVSS 7.8
CVE-2023-1289 [HIGH] ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: Several security issues were fixed in ImageMagick.
USN-6200-1 fixed vulnerabilities in ImageMagick. Unfortunately these fixes were
incomplete for Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. This update fixes the
problem.
Original advisory details:
It was discovered that ImageMagick incorrectly handled the "-authenticate"
option for password-protected PDF files. An attacker could possibly use
this issue to inject additional shell commands and perform arbitrary code
execution. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-29599)
It was discovered that ImageMagick incorrectly handled certain values
when processing PDF files. If a user or automated system using ImageMagick
were tricked into opening a specially crafted PDF file, an attacker co
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2023-07-04·CVSS 7.8
CVE-2023-1289 [HIGH] ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: Several security issues were fixed in ImageMagick.
It was discovered that ImageMagick incorrectly handled the "-authenticate"
option for password-protected PDF files. An attacker could possibly use
this issue to inject additional shell commands and perform arbitrary code
execution. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-29599)
It was discovered that ImageMagick incorrectly handled certain values
when processing PDF files. If a user or automated system using ImageMagick
were tricked into opening a specially crafted PDF file, an attacker could
exploit this to cause a denial of service. This issue only affected Ubuntu
20.04 LTS. (CVE-2021-20224)
Zhang Xiaohui discovered that ImageMagick incorrectly handled certain
values when proce
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2022-11-24·CVSS 5.5
CVE-2021-20313 [MEDIUM] ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: Several security issues were fixed in ImageMagick.
USN-5736-1 fixed vulnerabilities in ImageMagick. This update provides the
corresponding updates for Ubuntu 20.04 ESM and Ubuntu 22.04 ESM. One of the
issues, CVE-2021-20224, only affected Ubuntu 20.04 ESM, while
CVE-2021-20245, CVE-2021-3574, CVE-2021-4219 and CVE-2022-1114 only
affected Ubuntu 22.04 ESM.
Original advisory details:
It was discovered that ImageMagick incorrectly handled certain values
when processing PDF files. If a user or automated system using ImageMagick
were tricked into opening a specially crafted PDF file, an attacker could
exploit this to cause a denial of service. This issue only affected Ubuntu
14.04 ESM, Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2021-20224)
Zhang
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2022-11-24·CVSS 5.5
CVE-2021-20313 [MEDIUM] ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: Several security issues were fixed in ImageMagick.
It was discovered that ImageMagick incorrectly handled certain values
when processing PDF files. If a user or automated system using ImageMagick
were tricked into opening a specially crafted PDF file, an attacker could
exploit this to cause a denial of service. This issue only affected Ubuntu
14.04 ESM, Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2021-20224)
Zhang Xiaohui discovered that ImageMagick incorrectly handled certain
values when processing image data. If a user or automated system using
ImageMagick were tricked into opening a specially crafted image, an
attacker could exploit this to cause a denial of service. This issue only
affected Ubuntu 18.04 LTS and Ubuntu 22.10. (CVE-2021-2024
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2021-11-29·CVSS 5.5
CVE-2021-20244 [MEDIUM] ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: Several security issues were fixed in ImageMagick.
It was discovered that ImageMagick incorrectly handled certain values
when processing visual effects based image files. By tricking a user into
opening a specially crafted image file, an attacker could crash the
application causing a denial of service. (CVE-2021-20244)
It was discovered that ImageMagick incorrectly handled certain values
when performing resampling operations. By tricking a user into opening
a specially crafted image file, an attacker could crash the application
causing a denial of service. (CVE-2021-20246)
It was discovered that ImageMagick incorrectly handled certain values
when processing visual effects based image files. By tricking a user into
opening a specially crafted
Red Hat
ImageMagick: Cipher leak when the calculating signatures in TransformSignatureof MagickCore/signature.c
vendor_redhat·2021-02-25·CVSS 7.5
CVE-2021-20313 [HIGH] CWE-200 ImageMagick: Cipher leak when the calculating signatures in TransformSignatureof MagickCore/signature.c
ImageMagick: Cipher leak when the calculating signatures in TransformSignatureof MagickCore/signature.c
A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in TransformSignature is possible. The highest threat from this vulnerability is to data confidentiality.
A flaw was found in ImageMagick. A potential cipher leak when the calculate signatures in TransformSignature is possible. The highest threat from this vulnerability is to data confidentiality.
Package: ImageMagick (Red Hat Enterprise Linux 6) - Out of support scope
Package: ImageMagick (Red Hat Enterprise Linux 7) - Under investigation
Debian
CVE-2021-20313: imagemagick - A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher le...
vendor_debian·2021·CVSS 7.5
CVE-2021-20313 [HIGH] CVE-2021-20313: imagemagick - A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher le...
A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in TransformSignature is possible. The highest threat from this vulnerability is to data confidentiality.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.60+dfsg-1.5)
bullseye: resolved (fixed in 8:6.9.11.60+dfsg-1.3+deb11u4)
forky: resolved (fixed in 8:6.9.11.60+dfsg-1.5)
sid: resolved (fixed in 8:6.9.11.60+dfsg-1.5)
trixie: resolved (fixed in 8:6.9.11.60+dfsg-1.5)
OSV
imagemagick vulnerabilities
osv·2024-07-25·CVSS 7.8
[HIGH] imagemagick vulnerabilities
imagemagick vulnerabilities
USN-6200-1 fixed vulnerabilities in ImageMagick. Unfortunately these fixes were
incomplete for Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. This update fixes the
problem.
Original advisory details:
It was discovered that ImageMagick incorrectly handled the "-authenticate"
option for password-protected PDF files. An attacker could possibly use
this issue to inject additional shell commands and perform arbitrary code
execution. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-29599)
It was discovered that ImageMagick incorrectly handled certain values
when processing PDF files. If a user or automated system using ImageMagick
were tricked into opening a specially crafted PDF file, an attacker could
exploit this to cause a denial of service. This issue only affec
OSV
imagemagick vulnerabilities
osv·2023-07-04·CVSS 7.8
CVE-2020-29599 [HIGH] imagemagick vulnerabilities
imagemagick vulnerabilities
It was discovered that ImageMagick incorrectly handled the "-authenticate"
option for password-protected PDF files. An attacker could possibly use
this issue to inject additional shell commands and perform arbitrary code
execution. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-29599)
It was discovered that ImageMagick incorrectly handled certain values
when processing PDF files. If a user or automated system using ImageMagick
were tricked into opening a specially crafted PDF file, an attacker could
exploit this to cause a denial of service. This issue only affected Ubuntu
20.04 LTS. (CVE-2021-20224)
Zhang Xiaohui discovered that ImageMagick incorrectly handled certain
values when processing image data. If a user or automated system using
ImageMagick we
OSV
imagemagick vulnerabilities
osv·2022-11-24·CVSS 5.5
CVE-2021-20224 [MEDIUM] imagemagick vulnerabilities
imagemagick vulnerabilities
USN-5736-1 fixed vulnerabilities in ImageMagick. This update provides the
corresponding updates for Ubuntu 20.04 ESM and Ubuntu 22.04 ESM. One of the
issues, CVE-2021-20224, only affected Ubuntu 20.04 ESM, while
CVE-2021-20245, CVE-2021-3574, CVE-2021-4219 and CVE-2022-1114 only
affected Ubuntu 22.04 ESM.
Original advisory details:
It was discovered that ImageMagick incorrectly handled certain values
when processing PDF files. If a user or automated system using ImageMagick
were tricked into opening a specially crafted PDF file, an attacker could
exploit this to cause a denial of service. This issue only affected Ubuntu
14.04 ESM, Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2021-20224)
Zhang Xiaohui discovered that ImageMagick incorrectly handled certain
val
OSV
imagemagick vulnerabilities
osv·2022-11-24·CVSS 5.5
CVE-2021-20224 [MEDIUM] imagemagick vulnerabilities
imagemagick vulnerabilities
It was discovered that ImageMagick incorrectly handled certain values
when processing PDF files. If a user or automated system using ImageMagick
were tricked into opening a specially crafted PDF file, an attacker could
exploit this to cause a denial of service. This issue only affected Ubuntu
14.04 ESM, Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2021-20224)
Zhang Xiaohui discovered that ImageMagick incorrectly handled certain
values when processing image data. If a user or automated system using
ImageMagick were tricked into opening a specially crafted image, an
attacker could exploit this to cause a denial of service. This issue only
affected Ubuntu 18.04 LTS and Ubuntu 22.10. (CVE-2021-20241)
Zhang Xiaohui discovered that ImageMagick incorrectly handled ce
GHSA
GHSA-vrm6-xcmv-x82r: A flaw was found in ImageMagick in versions before 7
ghsa_unreviewed·2022-05-24
CVE-2021-20313 [HIGH] CWE-200 GHSA-vrm6-xcmv-x82r: A flaw was found in ImageMagick in versions before 7
A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in TransformSignature is possible. The highest threat from this vulnerability is to data confidentiality.
OSV
imagemagick vulnerabilities
osv·2021-11-29·CVSS 5.5
CVE-2021-20244 [MEDIUM] imagemagick vulnerabilities
imagemagick vulnerabilities
It was discovered that ImageMagick incorrectly handled certain values
when processing visual effects based image files. By tricking a user into
opening a specially crafted image file, an attacker could crash the
application causing a denial of service. (CVE-2021-20244)
It was discovered that ImageMagick incorrectly handled certain values
when performing resampling operations. By tricking a user into opening
a specially crafted image file, an attacker could crash the application
causing a denial of service. (CVE-2021-20246)
It was discovered that ImageMagick incorrectly handled certain values
when processing visual effects based image files. By tricking a user into
opening a specially crafted image file, an attacker could crash the
application causing a denial
OSV
CVE-2021-20313: A flaw was found in ImageMagick in versions before 7
osv·2021-05-11·CVSS 7.5
CVE-2021-20313 [HIGH] CVE-2021-20313: A flaw was found in ImageMagick in versions before 7
A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in TransformSignature is possible. The highest threat from this vulnerability is to data confidentiality.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1947019https://lists.debian.org/debian-lts-announce/2021/06/msg00000.htmlhttps://lists.debian.org/debian-lts-announce/2023/05/msg00020.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1947019https://lists.debian.org/debian-lts-announce/2021/06/msg00000.htmlhttps://lists.debian.org/debian-lts-announce/2023/05/msg00020.html
2021-05-11
Published