Back to bug 2167594

Who When What Removed Added
Sandipan Roy 2023-02-07 05:06:13 UTC CC jhorak
Sandipan Roy 2023-02-07 05:06:44 UTC Blocks 2167598
Sandipan Roy 2023-02-07 05:09:31 UTC Depends On 2167600, 2167599, 2167601
TEJ RATHI 2023-02-08 05:20:10 UTC CC bdettelb, drieden, ikanias, jary, rravi, tohughes
TEJ RATHI 2023-02-09 07:22:35 UTC Fixed In Version ImaeMagick 7.1.0-52, ImageMagick 6.9.12-67
TEJ RATHI 2023-02-09 07:39:37 UTC Fixed In Version ImaeMagick 7.1.0-52, ImageMagick 6.9.12-67 ImageMagick 7.1.0-52, ImageMagick 6.9.12-67
TEJ RATHI 2023-02-09 09:24:28 UTC Doc Text An information disclosure vulnerability was discovered in ImageMagick, that allows an attacker to read arbitrary files from a server when parsing an image. This happens when the program is parsing a PNG image. If Imagemagick has permission to read other arbitrary files, the resulting image after the parsing process could have been embedded with contents from another file on the machine.
Sandipan Roy 2023-02-09 11:15:12 UTC CC rhel8-maint
Sandipan Roy 2023-02-09 11:16:39 UTC CC rhel8-maint
Sandipan Roy 2023-02-09 11:17:02 UTC CC rhel8-maint
TEJ RATHI 2023-02-09 11:24:55 UTC CC rhel8-maint
RaTasha Tillery-Smith 2023-02-09 13:00:13 UTC Doc Text An information disclosure vulnerability was discovered in ImageMagick, that allows an attacker to read arbitrary files from a server when parsing an image. This happens when the program is parsing a PNG image. If Imagemagick has permission to read other arbitrary files, the resulting image after the parsing process could have been embedded with contents from another file on the machine. An information disclosure vulnerability was found in ImageMagick. This flaw allows an attacker to read arbitrary files from a server when parsing an image and happens when the program is parsing a PNG image. If ImageMagick has permission to read other arbitrary files, the resulting image could have been embedded with contents from another file on the machine after the parsing process.
Sergio Basto 2023-02-14 11:48:29 UTC CC sergio
Sergio Basto 2023-02-26 21:11:43 UTC CC sergio
TEJ RATHI 2023-03-27 12:23:01 UTC Flags needinfo?(jhorak)
Red Hat Bugzilla 2023-05-15 18:09:12 UTC CC drieden
Red Hat Bugzilla 2023-07-07 08:33:58 UTC Assignee security-response-team nobody

Back to bug 2167594