OS Command Injection in ImageMagick - CVE-2023-34153

 

OS Command Injection in ImageMagick - CVE-2023-34153

Published: June 1, 2023


Vulnerability identifier: #VU76764
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-34153
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation when processing video:vsync or video:pixel-format options in VIDEO encoding/decoding. A remote unauthenticated attacker can pass specially crafted data to the application and execute arbitrary OS commands on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

ImageMagick
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Fedora
Development Tools Module
Desktop Applications Module
openSUSE Leap
openEuler
ImageMagick
libMagickWand-7_Q16HDRI10
ImageMagick-doc
libMagickCore-7_Q16HDRI10-32bit-debuginfo
libMagick++-7_Q16HDRI5-32bit-debuginfo
libMagick++-7_Q16HDRI5-32bit
libMagickWand-7_Q16HDRI10-32bit
ImageMagick-devel-32bit
libMagick++-devel-32bit
libMagickCore-7_Q16HDRI10-32bit
libMagickWand-7_Q16HDRI10-32bit-debuginfo
ImageMagick-debuginfo
libMagick++-7_Q16HDRI5-debuginfo
perl-PerlMagick
libMagickCore-7_Q16HDRI10
ImageMagick-devel
ImageMagick-extra
libMagickCore-7_Q16HDRI10-debuginfo
libMagick++-devel
ImageMagick-extra-debuginfo
libMagickWand-7_Q16HDRI10-debuginfo
perl-PerlMagick-debuginfo
libMagick++-7_Q16HDRI5
ImageMagick-debugsource
ImageMagick-config-7-SUSE
ImageMagick-config-7-upstream
ImageMagick-help
ImageMagick-perl
ImageMagick-c++-devel
ImageMagick-c++

How to mitigate CVE-2023-34153

Install updates from vendor's website.

ImageMagick - update to 7.1.1-10
ImageMagick - addressed in versions 6.9.12.93-1.el8, 6.9.12.93-1.el9, 6.9.12.93-1.fc37, 7.1.1.10-1.fc38, 7.1.1.11-1.fc38
libMagickWand-7_Q16HDRI10 - update to 7.1.0.9-150400.6.21.1
ImageMagick-doc - update to 7.1.0.9-150400.6.21.1
libMagickCore-7_Q16HDRI10-32bit-debuginfo - update to 7.1.0.9-150400.6.21.1
libMagick++-7_Q16HDRI5-32bit-debuginfo - update to 7.1.0.9-150400.6.21.1
libMagick++-7_Q16HDRI5-32bit - update to 7.1.0.9-150400.6.21.1
libMagickWand-7_Q16HDRI10-32bit - update to 7.1.0.9-150400.6.21.1
ImageMagick-devel-32bit - update to 7.1.0.9-150400.6.21.1
libMagick++-devel-32bit - update to 7.1.0.9-150400.6.21.1
libMagickCore-7_Q16HDRI10-32bit - update to 7.1.0.9-150400.6.21.1
libMagickWand-7_Q16HDRI10-32bit-debuginfo - update to 7.1.0.9-150400.6.21.1
ImageMagick-debuginfo - update to 7.1.0.9-150400.6.21.1
libMagick++-7_Q16HDRI5-debuginfo - update to 7.1.0.9-150400.6.21.1
perl-PerlMagick - update to 7.1.0.9-150400.6.21.1
libMagickCore-7_Q16HDRI10 - update to 7.1.0.9-150400.6.21.1
ImageMagick-devel - update to 7.1.0.9-150400.6.21.1
ImageMagick-extra - update to 7.1.0.9-150400.6.21.1
libMagickCore-7_Q16HDRI10-debuginfo - update to 7.1.0.9-150400.6.21.1
libMagick++-devel - update to 7.1.0.9-150400.6.21.1
ImageMagick-extra-debuginfo - update to 7.1.0.9-150400.6.21.1
libMagickWand-7_Q16HDRI10-debuginfo - update to 7.1.0.9-150400.6.21.1
ImageMagick - update to 7.1.0.9-150400.6.21.1
perl-PerlMagick-debuginfo - update to 7.1.0.9-150400.6.21.1
libMagick++-7_Q16HDRI5 - update to 7.1.0.9-150400.6.21.1
ImageMagick-debugsource - update to 7.1.0.9-150400.6.21.1
ImageMagick-config-7-SUSE - update to 7.1.0.9-150400.6.21.1
ImageMagick-config-7-upstream - update to 7.1.0.9-150400.6.21.1
ImageMagick-debugsource - update to 7.1.1.8-2
ImageMagick-help - update to 7.1.1.8-2
ImageMagick-devel - update to 7.1.1.8-2
ImageMagick-perl - update to 7.1.1.8-2
ImageMagick-c++-devel - update to 7.1.1.8-2
ImageMagick-c++ - update to 7.1.1.8-2
ImageMagick-debuginfo - update to 7.1.1.8-2
ImageMagick - update to 7.1.1.8-2

External References

Related Security Bulletins