Computer Security
[EN] securityvulns.ru
no-pyccku



ImageMagic code execution
Published:09.12.2010
Source:BUGTRAQ
SecurityVulns ID:11285
Type:library
Level:4/10
Description:Configuration file from current directory is used.
Affected:IMAGEMAGICK : ImageMagick 6.6
CVE:CVE-2010-4167 (Untrusted search path vulnerability in configure.c in ImageMagick before 6.6.5-5, when MAGICKCORE_INSTALLED_SUPPORT is defined, allows local users to gain privileges via a Trojan horse configuration file in the current working directory.)
Original documentdocumentUBUNTU, [USN-1028-1] ImageMagick vulnerability (09.12.2010)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru