CVE-2022-44268
Description
ImageMagick 7.1.0-49 is vulnerable to information disclosure via crafted PNG files, allowing arbitrary file read if the process has permissions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
ImageMagick 7.1.0-49 is vulnerable to information disclosure via crafted PNG files, allowing arbitrary file read if the process has permissions.
Vulnerability
ImageMagick version 7.1.0-49 is vulnerable to an information disclosure flaw when parsing PNG images. An attacker can craft a PNG file with a specially crafted text chunk that, when processed (e.g., during a resize operation), causes the resulting image to embed the content of an arbitrary file from the filesystem [1]. The vulnerability only arises if the magick binary has read permissions for the targeted file.
Exploitation
To exploit the vulnerability, an attacker submits a maliciously crafted PNG image to the target system where ImageMagick processes it. No authentication is required beyond the ability to upload or present a PNG file to the application (e.g., via a web upload form or command-line invocation). The processing step (such as convert, identify, or any tool that parses the PNG) triggers the file read [1]. The attacker does not need write access on the target system.
Impact
Successful exploitation results in information disclosure: the output image contains the contents of any file that the ImageMagick process can read. This can leak sensitive data such as application configuration files, environment variables, SSH keys, or source code. The impact is limited to file content exposure; arbitrary code execution or modification of data is not achieved directly.
Mitigation
The vulnerability was fixed in later releases of ImageMagick. Upgrading to version 7.1.0-50 or newer (the current stable release as of the advisory is 7.1.2-23) eliminates the flaw [1]. If upgrading is not immediately possible, organizations can restrict file system access for the ImageMagick process using security policies (e.g., policy.xml to limit allowed file paths) and avoid processing PNG images from untrusted sources.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
27- Range: = 7.1.0-49
- osv-coords26 versionspkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Tumbleweedpkg:rpm/suse/ImageMagick&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/suse/ImageMagick&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-ESPOSpkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP4pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP4pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Real%20Time%2015%20SP3pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSSpkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP5pkg:rpm/suse/ImageMagick&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/ImageMagick&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209
< 7.0.7.34-150200.10.42.1+ 25 more
- (no CPE)range: < 7.0.7.34-150200.10.42.1
- (no CPE)range: < 7.1.1.17-1.1
- (no CPE)range: < 7.0.7.34-150200.10.42.1
- (no CPE)range: < 7.0.7.34-150200.10.42.1
- (no CPE)range: < 7.0.7.34-150000.3.123.1
- (no CPE)range: < 7.0.7.34-150200.10.42.1
- (no CPE)range: < 7.0.7.34-150200.10.42.1
- (no CPE)range: < 7.0.7.34-150200.10.42.1
- (no CPE)range: < 7.1.0.9-150400.6.12.1
- (no CPE)range: < 7.1.0.9-150400.6.12.1
- (no CPE)range: < 7.0.7.34-150200.10.42.1
- (no CPE)range: < 6.8.8.1-71.183.1
- (no CPE)range: < 6.8.8.1-71.183.1
- (no CPE)range: < 6.8.8.1-71.183.1
- (no CPE)range: < 7.0.7.34-150000.3.123.1
- (no CPE)range: < 7.0.7.34-150200.10.42.1
- (no CPE)range: < 7.0.7.34-150200.10.42.1
- (no CPE)range: < 6.8.8.1-71.183.1
- (no CPE)range: < 6.8.8.1-71.183.1
- (no CPE)range: < 7.0.7.34-150000.3.123.1
- (no CPE)range: < 7.0.7.34-150200.10.42.1
- (no CPE)range: < 7.0.7.34-150200.10.42.1
- (no CPE)range: < 6.8.8.1-71.183.1
- (no CPE)range: < 6.8.8.1-71.183.1
- (no CPE)range: < 6.8.8.1-71.183.1
- (no CPE)range: < 6.8.8.1-71.183.1
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
7- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AINSUL2QBKETGYRPA7XSCMJWLUB44M6S/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZZLLS37P67CMBRML6OCG42GPCKGRCJNV/mitrevendor-advisory
- www.debian.org/security/2023/dsa-5347mitrevendor-advisory
- lists.debian.org/debian-lts-announce/2023/03/msg00008.htmlmitremailing-list
- packetstormsecurity.com/files/171727/ImageMagick-7.1.0-48-Arbitrary-File-Read.htmlmitre
- imagemagick.orgmitre
- www.metabaseq.com/imagemagick-zero-days/mitre
News mentions
0No linked articles in our index yet.