UBUNTU-CVE-2020-29599
Dashboard / Vulnerabilities / UBUNTU-CVE-2020-29599
UBUNTU-CVE-2020-29599
Summary:
Details: ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which allows setting a password for password-protected PDF files. The user-controlled password was not properly escaped/sanitized and it was therefore possible to inject additional shell commands via coders/pdf.c.
References: https://ubuntu.com/security/CVE-2020-29599, https://github.com/ImageMagick/ImageMagick/discussions/2851, https://insert-script.blogspot.com/2020/11/imagemagick-shell-injection-via-pdf.html, https://ubuntu.com/security/notices/USN-6200-1, https://www.cve.org/CVERecord?id=CVE-2020-29599
Affected packages
Package
Name: imagemagick
Purl: pkg:deb/ubuntu/imagemagick@8:6.9.10.23+dfsg-2.1ubuntu11.9?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
