ImageMagick Information Leakage Vulnerability (CVE-2018-5358)
ImageMagick Information Leakage Vulnerability (CVE-2018-5358)
Release date:
Updated on:
Affected Systems:
ImageMagick ImageMagick 7.0.7-22 Q16
Description:
Bugtraq id: 102762
CVE (CAN) ID: CVE-2018-5358
ImageMagick is an open-source image viewing and editing tool on Unix/Linux platforms.
In ImageMagick 7.0.7-22 Q16, the coders/json. c/EncodeImageAttributes function has the information leakage vulnerability. After successful exploitation, attackers can obtain sensitive information.
<* Source: Nsfocus Security Team (security@nsfocus.com)
*>
Suggestion:
Vendor patch:
ImageMagick
-----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://github.com/ImageMagick/ImageMagick/issues/939
Http://www.imagemagick.org/
Https://bugzilla.redhat.com/show_bug.cgi? Id = 1534380
Https://access.redhat.com/security/cve/CVE-2018-5358
Use ImageMagick to draw a three-color schematic diagram
In Linux, PHP supports ImageMagick and MagicWandForPHP.
Image Magic with ImageMagick in Linux
Cross-compile ImageMagick in Ubuntu 16.04
Installation of ImageMagick and MagicWand For PHP in Linux
Install ImageMagick and JMagick in Linux
The ImageMagick compiled on Linux system is migrated to another machine.
For details about ImageMagick, click here
ImageMagick: click here