Insecure library loading in ImageMagick - CVE-2024-41817
Published: July 28, 2024 / Updated: January 5, 2025
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the application loads shared libraries and configuration files in an insecure manner when setting MAGICK_CONFIGURE_PATH and LD_LIBRARY_PATH environment variables while executing. A local user can place a malicious file into the current working directory and trick the victim into executing ImageMagic, resulting in code execution.
Affected software
Oracle Communications Operations Monitor
Communications Unified Assurance
Anolis OS
ImageMagick
ImageMagick-c++
ImageMagick-c++-devel
ImageMagick-devel
ImageMagick-djvu
ImageMagick-doc
ImageMagick-libs
ImageMagick-perl
How to mitigate CVE-2024-41817
Communications Unified Assurance - update to 6.0.5
ImageMagick - update to 7.1.1.36-1
ImageMagick-c++ - update to 7.1.1.36-1
ImageMagick-c++-devel - update to 7.1.1.36-1
ImageMagick-devel - update to 7.1.1.36-1
ImageMagick-djvu - update to 7.1.1.36-1
ImageMagick-doc - update to 7.1.1.36-1
ImageMagick-libs - update to 7.1.1.36-1
ImageMagick-perl - update to 7.1.1.36-1