🛡️ USN-6200-1 — imagemagick

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

imagemagick vulnerabilities

It was discovered that ImageMagick incorrectly handled the "-authenticate"

option for password-protected PDF files. An attacker could possibly use

this issue to inject additional shell commands and perform arbitrary code

execution. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-29599)

It was discovered that ImageMagick incorrectly handled certain values

when processing PDF files. If a user or automated system using ImageMagick

were tricked into opening a specially crafted PDF file, an attacker could

exploit this to cause a denial of service. This issue only affected Ubuntu

20.04 LTS. (CVE-2021-20224)

Zhang Xiaohui discovered that ImageMagick incorrectly handled certain

values when processing image data. If a user or automated system using

ImageMagick were tricked into opening a specially crafted image, an

attacker could exploit this to cause a denial of service. This issue only

affected Ubuntu 20.04 LTS. (CVE-2021-20241, CVE-2021-20243)

It was discovered that ImageMagick incorrectly handled certain values

when processing visual effects based image files. By tricking a user into

opening a specially crafted image file, an attacker could crash the

application causing a denial of service. This issue only affected Ubuntu

20.04 LTS. (CVE-2021-20244, CVE-2021-20309)

It was discovered that ImageMagick incorrectly handled certain values

when performing resampling operations. By tricking a user into opening

a specially crafted image file, an attacker could crash the application

causing a denial of service. This issue only affected Ubuntu 20.04 LTS.

(CVE-2021-20246)

It was discovered that ImageMagick incorrectly handled certain values

when processing thumbnail image data. By tricking a user into opening

a specially crafted image file, an attacker could crash the application

causing a denial of service. This issue only affected Ubuntu 20.04 LTS.

(CVE-2021-20312)

It was discovered that ImageMagick incorrectly handled memory cleanup

when performing certain cryptographic operations. Under certain conditions

sensitive cryptographic information could be disclosed. This issue only

affected Ubuntu 20.04 LTS. (CVE-2021-20313)

It was discovered that ImageMagick did not use the correct rights when

specifically excluded by a module policy. An attacker could use this issue

to read and write certain restricted files. This issue only affected Ubuntu

20.04 LTS. (CVE-2021-39212)

It was discovered that ImageMagick incorrectly handled memory under certain

circumstances. If a user were tricked into opening a specially crafted

image file, an attacker could possibly exploit this issue to cause a denial

of service or other unspecified impact. This issue only affected Ubuntu

20.04 LTS. (CVE-2022-28463, CVE-2022-32545, CVE-2022-32546, CVE-2022-32547)

It was discovered that ImageMagick incorrectly handled memory under certain

circumstances. If a user were tricked into opening a specially crafted

image file, an attacker could possibly exploit this issue to cause a denial

of service or other unspecified impact. This issue only affected Ubuntu

22.04 LTS, Ubuntu 22.10, and Ubuntu 23.04. (CVE-2021-3610, CVE-2023-1906,

CVE-2023-3428)

It was discovered that ImageMagick incorrectly handled certain values

when processing specially crafted SVG files. By tricking a user into

opening a specially crafted SVG file, an attacker could crash the

application causing a denial of service. This issue only affected Ubuntu

20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 22.10, and Ubuntu 23.04. (CVE-2023-1289)

It was discovered that ImageMagick incorrectly handled memory under certain

circumstances. If a user were tricked into opening a specially crafted

tiff file, an attacker could possibly exploit this issue to cause a denial

of service or other unspecified impact. This issue only affected Ubuntu

22.04 LTS, Ubuntu 22.10, and Ubuntu 23.04. (CVE-2023-3195)

It was discovered that ImageMagick incorrectly handled memory under certain

circumstances. If a user were tricked into opening a specially crafted

image file, an attacker could possibly exploit this issue to cause a denial

of service or other unspecified impact. (CVE-2023-34151)

Affected software

USN-6200-1 is recorded against 1 package.

  • imagemagick (fixed in 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+esm2)

Timeline and source

Published on 4 July 2023 and last revised on 25 June 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

ubuntu.com (Advisory)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2023-07-04
Updated 2026-08-12
Modified 2026-06-25
Fix URL N/A

Affected Packages

Software From version Fixed in
imagemagick 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+esm2

References

Similar Threats

Free Vulnerability Check

Is your site affected by USN-6200-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against USN-6200-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.