CVE-2019-13574

Description

In lib/mini_magick/image.rb in MiniMagick before 4.9.4, a fetched remote image filename could cause remote command execution because Image.open input is directly passed to Kernel#open, which accepts a | character followed by a command.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
29.491

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2019-13574 are fixed in Ruby-mini_magick 4.9.4Windows
ruby-mini-magick security update(DSA-4481-1) ruby-mini-magick_4.5.1-1+deb9u1_all.debLinux
ruby-mini-magick security update(DSA-4481-1) ruby-mini-magick_4.9.2-1+deb10u1_all.debLinux
Vulnerabilities CVE-2019-13574 are fixed in Ruby-mini_magick for Linux 4.9.4Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234