access.redhat.com
https://access.redhat.com/security/cve/CVE-2023-34152 CVE-2023-34152
CRITICAL
Record summary
CVE-2023-34152 has a selected CVSS score of 9.8 (critical); EIP currently links 2 repository PoCs.
Description
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 2
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 13, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ImageMagick | CVE List | ImageMagick-6.7 | affected |
Proofs of concept
2Repository PoCs
GitHubovergrowncarrot1/ImageTragick_CVE-2023-34152Repository PoCby overgrowncarrot1Stars: 10Not analyzed2 files
GitHubSudoIndividual/CVE-2023-34152Repository PoCby SudoIndividualStars: 5Not analyzed2 files
References
6bugzilla.redhat.com
https://bugzilla.redhat.com/show_bug.cgi?id=2210659 github.com
https://github.com/ImageMagick/ImageMagick/issues/6339 FEDORA-2023-edbdccae2aVendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UFQJCYJ23HWHNDOVKBHZQ7HCXXL6MM3 FEDORA-2023-d53831b69dVendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2ZUHZXQ2C3JZYKPW4XHCMVVL467MA2V nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-34152