ImageMagick 在 7.1.2-30 版本之前存在一个时间检查-时间使用(time-of-check-time-of-use)漏洞,位于 Windows 平台上的路径策略执行环节。攻击者可以利用符号链接的竞争条件(race condition),在策略验证和文件访问之间替换符号链接,从而绕过读取或写入限制,进而读写策略中禁止访问的文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ImageMagick | ImageMagick | < 7.1.2-30 |
affected |
7.1.2-30 |
unaffected | ||
< 6.9.13-55 |
affected | ||
6.9.13-55 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ImageMagick | ImageMagick | 0 ~ 7.1.2-30 | - |
|
| ImageMagick | ImageMagick | 0 ~ 6.9.13-55 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86420 | 3.7 LOW | ImageMagick before 7.1.2-30 Denial of Service Memory Budget |
| CVE-2026-86421 | 3.7 LOW | ImageMagick before 7.1.2-30 Memory Leak via MSL decoder |
| CVE-2026-86425 | 3.3 LOW | ImageMagick before 7.1.2-30 Heap-use-after-free via Layer |
| CVE-2026-86423 | 3.3 LOW | ImageMagick before 7.1.2-30 Heap-use-after-free via GetList |
| CVE-2026-86424 | 2.5 LOW | ImageMagick before 7.1.2-30 Path Traversal via TOCTOU Symlink Race |
No comments yet