Improper Input Validation Affecting imagemagick Open this link in a new tab package, versions >=0.0.0
Exploit Maturity
Proof of concept
Attack Complexity
Low
User Interaction
Required
Scope
Changed
Integrity
High
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications-
snyk-id
SNYK-COCOAPODS-IMAGEMAGICK-471249
-
published
2 Oct 2019
-
disclosed
4 May 2016
-
credit
Unknown
How to fix?
There is no fixed version for ImageMagick
.
Overview
ImageMagick is a pod that allows you to convert, edit and compose Images.
Affected versions of this package are vulnerable to Improper Input Validation. ImageMagick is vulnerable to server-side request forgery (SSRF). A malicious user can send a malicious .mvg file to force a HTTP, GET or FTP request a user.
References
- BUGTRAQ
- CONFIRM
- CONFIRM
- CONFIRM
- Debian Security Advisory
- Debian Security Announcement
- Exploit DB
- Gentoo Security Advisory
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- OpenSuse Security Announcement
- Oracle Security Bulletin
- Oracle Security Bulletin
- OSS security Advisory
- RedHat Security Advisory
- SLACKWARE
- Ubuntu Security Advisory