HTTP: ImageMagick PNG tEXt profile Arbitrary File Read

This signature detects attempts to exploit a known vulnerability against ImageMagick PNG tEXt profile. A successful attack can lead to sensitive information disclosure.

Extended Description

ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded the content of an arbitrary. file (if the magick binary has permissions to read it).

Affected Products

Imagemagick imagemagick

References

CVE: CVE-2022-44268

Short Name
HTTP:IMAGEMAGICK-FILE-READ
Severity
Minor
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
Arbitrary CVE-2022-44268 File ImageMagick PNG Read profile tEXt
Release Date
03/02/2023
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3759
False Positive
Rarely
Vendors

Imagemagick

Found a potential security threat?