Executive brief
ImageMagick contains an improper input validation vulnerability, known as 'ImageTragick', affecting multiple coders including EPHEMERAL, HTTPS, and MVG. Remote attackers can execute arbitrary code by using shell metacharacters within a specially crafted image file.
Affected products
- ImageMagick ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1
Timeline
- 2016-05-03: disclosed: Public disclosure via oss-security mailing list
- 2024-09-09: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-09-09: other: Advisory publication date