GHSA-82mp-vp5c-9pf7MediumCVSS 6.1
ImageMagick: Policy Bypass in concatenate operation due to missing checks
🔗 CVE IDs covered (1)
📋 Description
The -concatenate operation is missing policy checks and that could result in both reading and writing to paths disallowed by the security policy.
🎯 Affected products17
- nuget/Magick.NET-Q16-AnyCPU:< 14.15.0
- nuget/Magick.NET-Q16-HDRI-AnyCPU:< 14.15.0
- nuget/Magick.NET-Q16-HDRI-OpenMP-arm64:< 14.15.0
- nuget/Magick.NET-Q16-HDRI-x64:< 14.15.0
- nuget/Magick.NET-Q16-HDRI-x86:< 14.15.0
- nuget/Magick.NET-Q16-OpenMP-arm64:< 14.15.0
- nuget/Magick.NET-Q16-OpenMP-x64:< 14.15.0
- nuget/Magick.NET-Q16-arm64:< 14.15.0
- nuget/Magick.NET-Q16-x64:< 14.15.0
- nuget/Magick.NET-Q16-x86:< 14.15.0
- nuget/Magick.NET-Q8-AnyCPU:< 14.15.0
- nuget/Magick.NET-Q8-OpenMP-arm64:< 14.15.0
- nuget/Magick.NET-Q8-OpenMP-x64:< 14.15.0
- nuget/Magick.NET-Q8-arm64:< 14.15.0
- nuget/Magick.NET-Q8-x64:< 14.15.0
- nuget/Magick.NET-Q8-x86:< 14.15.0
- nuget/Magick.NET-Q16-HDRI-arm64:< 14.15.0