Description

The PasskeyEncipherImage method is vulnerable to information disclosure via AES-CTR nonce reuse. ImageMagick has update the documentation on its website to make it more clear that this is happening: https://imagemagick.org/cipher/

Description source: GitHub Advisory

Affected products and versions

Showing 12 of 17
ProductSourceVersion rangeStatus
GitHub AdvisoryBefore 14.12.0 · Fixed in 14.12.0affected
GitHub AdvisoryBefore 14.12.0 · Fixed in 14.12.0affected

Magick.NET-Q16-HDRI-OpenMP-arm64

Browse NuGet / Magick.NET-Q16-HDRI-OpenMP-arm64
GitHub AdvisoryBefore 14.12.0 · Fixed in 14.12.0affected
GitHub AdvisoryBefore 14.12.0 · Fixed in 14.12.0affected
GitHub AdvisoryBefore 14.12.0 · Fixed in 14.12.0affected
GitHub AdvisoryBefore 14.12.0 · Fixed in 14.12.0affected
GitHub AdvisoryBefore 14.12.0 · Fixed in 14.12.0affected
GitHub AdvisoryBefore 14.12.0 · Fixed in 14.12.0affected
GitHub AdvisoryBefore 14.12.0 · Fixed in 14.12.0affected
GitHub AdvisoryBefore 14.12.0 · Fixed in 14.12.0affected
GitHub AdvisoryBefore 14.12.0 · Fixed in 14.12.0affected
GitHub AdvisoryBefore 14.12.0 · Fixed in 14.12.0affected

References

3