Insecure library loading in ImageMagick - CVE-2024-41817

 

Insecure library loading in ImageMagick - CVE-2024-41817

Published: July 28, 2024 / Updated: January 5, 2025


Vulnerability identifier: #VU94793
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-41817
CWE-ID: CWE-427
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to the application loads shared libraries and configuration files in an insecure manner when setting MAGICK_CONFIGURE_PATH and LD_LIBRARY_PATH environment variables while executing. A local user can place a malicious file into the current working directory and trick the victim into executing ImageMagic, resulting in code execution.


Affected software

ImageMagick
Oracle Communications Operations Monitor
Communications Unified Assurance
Anolis OS
ImageMagick
ImageMagick-c++
ImageMagick-c++-devel
ImageMagick-devel
ImageMagick-djvu
ImageMagick-doc
ImageMagick-libs
ImageMagick-perl

How to mitigate CVE-2024-41817

Install updates from vendor's website.

ImageMagick - update to 7.1.1-36
Communications Unified Assurance - update to 6.0.5
ImageMagick - update to 7.1.1.36-1
ImageMagick-c++ - update to 7.1.1.36-1
ImageMagick-c++-devel - update to 7.1.1.36-1
ImageMagick-devel - update to 7.1.1.36-1
ImageMagick-djvu - update to 7.1.1.36-1
ImageMagick-doc - update to 7.1.1.36-1
ImageMagick-libs - update to 7.1.1.36-1
ImageMagick-perl - update to 7.1.1.36-1

External References

Related Security Bulletins