CVE-2021-4219Improper Input Validation in Imagemagick

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 73.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 23
Latest updateNov 24

Description

A flaw was found in ImageMagick. The vulnerability occurs due to improper use of open functions and leads to a denial of service. This flaw allows an attacker to crash the system.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

debiandebian/imagemagick< imagemagick 8:6.9.11.60+dfsg-1.5 (bookworm)
NVDimagemagick/imagemagick7.1.0-07.1.0-19+1
Debianimagemagick/imagemagick< 8:6.9.11.60+dfsg-1.3+deb11u2+3
Ubuntuimagemagick/imagemagick< 8:6.9.7.4+dfsg-16ubuntu6.14+4
CVEListV5imagemagick/imagemagickimagemagick 6.9.12-34, imagemagick 7.1.0-19

🔴Vulnerability Details

4
OSV
imagemagick vulnerabilities2022-11-24
OSV
imagemagick vulnerabilities2022-11-24
GHSA
GHSA-wrw9-5gqr-6wqh: A flaw was found in ImageMagick2022-03-24
OSV
CVE-2021-4219: A flaw was found in ImageMagick2022-03-23

📋Vendor Advisories

4
Ubuntu
ImageMagick vulnerabilities2022-11-24
Ubuntu
ImageMagick vulnerabilities2022-11-24
Red Hat
imagemagick: remote DoS in MagicCore/draw.c via crafted SVG file2021-12-22
Debian
CVE-2021-4219: imagemagick - A flaw was found in ImageMagick. The vulnerability occurs due to improper use of...2021