CVE-2024-41817

CVSS V2 None CVSS V3 None
Description
ImageMagick is a free and open-source software suite, used for editing and manipulating digital images. The `AppImage` version `ImageMagick` might use an empty path when setting `MAGICK_CONFIGURE_PATH` and `LD_LIBRARY_PATH` environment variables while executing, which might lead to arbitrary code execution by loading malicious configuration files or shared libraries in the current working directory while executing `ImageMagick`. The vulnerability is fixed in 7.11-36.
Overview
  • CVE ID
  • CVE-2024-41817
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-07-29T15:53:17.236Z
  • Last Modified Date
  • 2024-07-29T16:23:47.450Z
History
Created Old Value New Value Data Type Notes
2024-07-30 13:15:41 Added to TrackCVE