In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
No history.
Information
Published : 2020-03-18 19:15
Updated : 2024-11-21 04:23
NVD link : CVE-2019-12921
Mitre link : CVE-2019-12921
CVE.ORG link : CVE-2019-12921
JSON object : View
Products Affected
opensuse
- backports_sle
- leap
graphicsmagick
- graphicsmagick
debian
- debian_linux
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')