CVE-2021-4219
Published on: Not Yet Published
Last Modified on: 03/30/2022 03:52:00 PM UTC
Certain versions of Imagemagick from Imagemagick contain the following vulnerability:
A flaw was found in ImageMagick. The vulnerability occurs due to improper use of open functions and leads to a denial of service. This flaw allows an attacker to crash the system.
- CVE-2021-4219 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 5.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVSS2 Score: 4.3 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | NONE | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Specially crafted SVG hangs ImageMagick forever, possible to leverage DoS · Issue #4626 · ImageMagick/ImageMagick · GitHub | github.com text/html |
![]() |
Red Hat Customer Portal - Access to 24x7 support and knowledge | access.redhat.com text/html |
![]() |
2054611 – (CVE-2021-4219) CVE-2021-4219 imagemagick: remote DoS in MagicCore/draw.c via crafted SVG file | bugzilla.redhat.com text/html |
![]() |
Related QID Numbers
- 199045 Ubuntu Security Notification for ImageMagick Vulnerabilities (USN-5736-1)
- 296082 Oracle Solaris 11.4 Support Repository Update (SRU) 48.126.1 Missing (CPUJUL2022)
- 354798 Amazon Linux Security Advisory for ImageMagick : ALAS2-2023-1971
- 354809 Amazon Linux Security Advisory for ImageMagick : ALAS-2023-1696
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Imagemagick | Imagemagick | All | All | All | All |
- cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-4219 : A flaw was found in ImageMagick. The vulnerability occurs due to improper use of open functions and… twitter.com/i/web/status/1… | 2022-03-23 20:18:34 |
![]() |
DSM Version: 7.2-64561 | 2023-05-22 03:16:44 |