RULE(RULE ID:337826)

Rule General Information
Release Date: 2024-02-27
Rule Name: ImageMagick 7.1.0-51 Arbitrary File Reading Vulnerability (CVE-2022-44268)
Severity:
CVE ID:
Rule Protection Details
Description: ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded the content of an arbitrary. file (if the magick binary has permissions to read it).
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: ExploitDB:51261
https://www.metabaseq.com/imagemagick-zero-days/
https://www.debian.org/security/2023/dsa-5347
https://lists.fedoraproject.org/archives/list/package-announce
Solutions
Refer to the announcement or patch by the vendor: https://imagemagick.org/script/download.php