Wednesday, October 4, 2023
No Result
View All Result
Personal Safety News
  • Home
  • Domestic Violence
  • Crime
  • Personal Safety
  • Self Defense
  • Martial Arts
  • Bullying
  • More
    • Cyber Crimes
    • Stalking
    • Relationship Advice
    • MMA
Personal Safety News
  • Home
  • Domestic Violence
  • Crime
  • Personal Safety
  • Self Defense
  • Martial Arts
  • Bullying
  • More
    • Cyber Crimes
    • Stalking
    • Relationship Advice
    • MMA
Personal Safety News

Researchers Uncover New Bugs in In style ImageMagick Picture Processing Utility

by Personal Safety News
February 2, 2023
in Cyber Crimes
Reading Time: 2 mins read
245 7
A A
0
Home Cyber Crimes
Share on FacebookShare on Twitter


Feb 01, 2023Ravie LakshmananVulnerability

Cybersecurity researchers have disclosed particulars of two safety flaws within the open supply ImageMagick software program that would doubtlessly result in a denial-of-service (DoS) and knowledge disclosure.

The 2 points, which have been recognized by Latin American cybersecurity agency Metabase Q in model 7.1.0-49, have been addressed in ImageMagick model 7.1.0-52, launched in November 2022.

A quick description of the issues is as follows –

CVE-2022-44267 – A DoS vulnerability that arises when parsing a PNG picture with a filename that is a single sprint (“-“)
CVE-2022-44268 – An info disclosure vulnerability that may very well be exploited to learn arbitrary recordsdata from a server when parsing a picture

That mentioned, an attacker should have the ability to add a malicious picture to an internet site utilizing ImageMagick in order to weaponize the issues remotely. The specifically crafted picture, for its half, will be created by inserting a textual content chunk that specifies some metadata of the attacker’s selection (e.g., “-” for the filename).

ImageMagick Image Processing
ImageMagick Image Processing

“If the required filename is ‘-‘ (a single sprint), ImageMagick will attempt to learn the content material from normal enter doubtlessly leaving the method ready without end,” the researchers mentioned in a report shared with The Hacker Information.

In the identical method, if the filename refers to an precise file situated within the server (e.g., “/and many others/passwd”), a picture processing operation carried out on the enter might doubtlessly embed the contents of the distant file after it is full.

This isn’t the primary time safety vulnerabilities have been found in ImageMagick. In Could 2016, a number of flaws have been disclosed within the software program, one in all which, dubbed ImageTragick, might have been abused to realize distant code execution when processing user-submitted pictures.

A shell injection vulnerability was subsequently revealed in November 2020, whereby an attacker might insert arbitrary instructions when changing encrypted PDFs to photographs through the “-authenticate” command line parameter.

Discovered this text fascinating? Comply with us on Twitter  and LinkedIn to learn extra unique content material we put up.



Source link

Tags: BugsImageImageMagickPopularProcessingResearchersUncoverUtility
Share196Tweet123Share49Pin44Share34
Previous Post

Dana White’s Energy Slap League To Air Event Finale On Pay-per-view In March

Next Post

To Talk about the Newest Three Mass Shootings in California

Related Posts

Linux Vulnerability Exposes Hundreds of thousands of Programs to Assault
Cyber Crimes

Linux Vulnerability Exposes Hundreds of thousands of Programs to Assault

October 4, 2023
Nexusflow Slots AI Into SOC Automation
Cyber Crimes

Nexusflow Slots AI Into SOC Automation

October 3, 2023
Scattered Spider Getting SaaS-y within the Cloud
Cyber Crimes

Scattered Spider Getting SaaS-y within the Cloud

October 2, 2023
Microsoft Defender Flags Tor Browser as Win32/Malgent!MTB Malware
Cyber Crimes

Microsoft Defender Flags Tor Browser as Win32/Malgent!MTB Malware

October 2, 2023
FBI Warns of Rising Development of Twin Ransomware Assaults Focusing on U.S. Corporations
Cyber Crimes

FBI Warns of Rising Development of Twin Ransomware Assaults Focusing on U.S. Corporations

September 30, 2023
Securing AI: What You Ought to Know
Cyber Crimes

Securing AI: What You Ought to Know

October 1, 2023
Next Post
To Talk about the Newest Three Mass Shootings in California

To Talk about the Newest Three Mass Shootings in California

Is it Satisfaction That Retains Us from Forgiving Ourselves?

Is it Satisfaction That Retains Us from Forgiving Ourselves?

Be a part of us in Supporting Safer Web Day 2023: Join. Replicate. Defend.

Be a part of us in Supporting Safer Web Day 2023: Join. Replicate. Defend.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Trending
  • Comments
  • Latest
Cigna Well being Knowledge Leak: 17 Billion Data Uncovered

Cigna Well being Knowledge Leak: 17 Billion Data Uncovered

September 1, 2023
Blood-stained mattresses faraway from Idaho house of murdered college students

Blood-stained mattresses faraway from Idaho house of murdered college students

January 7, 2023
Instagram influencers Racquelle Marie Dolores Anteola, Melissa Dufour caught with $3 million of cocaine: feds

Instagram influencers Racquelle Marie Dolores Anteola, Melissa Dufour caught with $3 million of cocaine: feds

June 11, 2023
Be taught essentially the most highly effective groin kick for self-defense.

Be taught essentially the most highly effective groin kick for self-defense.

May 31, 2023
Ebony Alert for lacking Black kids awaits Newsom’s OK

Ebony Alert for lacking Black kids awaits Newsom’s OK

September 16, 2023
Extracting Encrypted Credentials From Frequent Instruments

Extracting Encrypted Credentials From Frequent Instruments

December 29, 2022
Azure AD Token Forging Approach in Microsoft Assault Extends Past Outlook, Wiz Studies

Azure AD Token Forging Approach in Microsoft Assault Extends Past Outlook, Wiz Studies

July 21, 2023
Massive Will increase In Classes Of Violent Victimization in America

Massive Will increase In Classes Of Violent Victimization in America

September 15, 2023
Tawanchai to proceed quest for two-sport glory at ONE Combat Night time 15

Tawanchai to proceed quest for two-sport glory at ONE Combat Night time 15

October 4, 2023
Artistic Mom-Daughter Date Concepts for Fall

Artistic Mom-Daughter Date Concepts for Fall

October 4, 2023
This week, a temblor reshaped California politics

This week, a temblor reshaped California politics

October 4, 2023
Linux Vulnerability Exposes Hundreds of thousands of Programs to Assault

Linux Vulnerability Exposes Hundreds of thousands of Programs to Assault

October 4, 2023
NYC man killed in random stabbing pictured smiling at wedding ceremony hours earlier

NYC man killed in random stabbing pictured smiling at wedding ceremony hours earlier

October 3, 2023
Daniel Cormier: Aljamain Sterling ‘ought to get a rematch with Sean O’Malley however he gained’t’

Daniel Cormier: Aljamain Sterling ‘ought to get a rematch with Sean O’Malley however he gained’t’

October 3, 2023
The invisible and infrequently very private OHS hazard – SafetyAtWorkBlog

The invisible and infrequently very private OHS hazard – SafetyAtWorkBlog

October 3, 2023
On 700 WLW’s The Invoice Cunningham Present: Discussing Nationwide Politics

On 700 WLW’s The Invoice Cunningham Present: Discussing Nationwide Politics

October 3, 2023
Personal Safety News

Get the latest news and follow the coverage of Domestic Violence, Self Defense, Crimes, Bullying, Martial Arts and more from the top trusted sources.

CATEGORIES

  • Bullying
  • Crime
  • Cyber Crimes
  • Domestic Violence
  • Martial Arts
  • MMA
  • Personal Safety
  • Relationship Advice
  • Self Defense
  • Stalking

LATEST UPDATES

  • Tawanchai to proceed quest for two-sport glory at ONE Combat Night time 15
  • Artistic Mom-Daughter Date Concepts for Fall
  • This week, a temblor reshaped California politics

Copyright © 2023 Personal Safety News.
Personal Safety News is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • Domestic Violence
  • Crime
  • Personal Safety
  • Self Defense
  • Martial Arts
  • Bullying
  • Cyber Crimes
  • Stalking
  • Relationship Advice
  • MMA

Copyright © 2023 Personal Safety News.
Personal Safety News is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In