A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in TransformSignature is possible. The highest threat from this vulnerability is to data confidentiality.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1947019 | issue tracking third party advisory patch |
https://lists.debian.org/debian-lts-announce/2021/06/msg00000.html | third party advisory mailing list |
https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html | mailing list |