In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG. References: https://github.com/d0ge/data-processing/blob/master/CVE-2019-12921.md http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/f780c290b4ab
Created GraphicsMagick tracking bugs for this issue: Affects: epel-all [bug 1851884] Affects: fedora-all [bug 1851882]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.