<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T09:31:52.216788+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-02155</id>
    <title>bdu:2023-02155</title>
    <updated>2026-10-04T09:31:52.230839+00:00</updated>
    <content>bdu:2023-02155</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-02155"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0969</id>
    <title>certfr-2025-avi-0969 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-04T09:31:52.230882+00:00</updated>
    <content>certfr-2025-avi-0969</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0969"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-6656</id>
    <title>EUVD-2026-6656</title>
    <updated>2026-10-04T09:31:52.230902+00:00</updated>
    <content>EUVD-2026-6656</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-6656"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-1289</id>
    <title>fkie_cve-2023-1289</title>
    <updated>2026-10-04T09:31:52.230913+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a remote attacker to pass a specially crafted SVG file that leads to a segmentation fault, generating many trash files in "/tmp," resulting in a denial of service. When ImageMagick crashes, it generates a lot of trash files. These trash files can be large if the SVG file contains many render actions. In a denial of service attack, if a remote attacker uploads an SVG file of size t, ImageMagick generates files of size 103*t. If an attacker uploads a 100M SVG, the server will generate about 10G.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-1289"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j96m-mjp6-99xr</id>
    <title>GHSA-j96m-mjp6-99xr — ImageMagick: Specially crafted SVG leads to segmentation fault and generate trash files in "/tmp", possible to leverage…</title>
    <updated>2026-10-04T09:31:52.230946+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> NuGet: Magick.NET-Q16-AnyCPU, NuGet: Magick.NET-Q16-HDRI-AnyCPU, NuGet: Magick.NET-Q16-HDRI-OpenMP-arm64, NuGet: Magick.NET-Q16-HDRI-arm64, NuGet: Magick.NET-Q16-HDRI-x64, NuGet: Magick.NET-Q16-HDRI-x86, NuGet: Magick.NET-Q16-OpenMP-arm64, NuGet: Magick.NET-Q16-OpenMP-x64, NuGet: Magick.NET-Q16-OpenMP-x86, NuGet: Magick.NET-Q16-arm64 and 9 more</p>
<p>### Summary
Specially crafted SVG file make segmentation fault and generate trash files in "/tmp", possible to leverage DoS.</p>
<p>### Operating system, version and so on</p>
<p>Linux,  Debian (Buster) LTS core 5.10 / Parrot OS 5.1 (Electro Ara)</p>
<p>### Tested ImageMagick version</p>
<p>6.9.11-60, 7.1.0-62</p>
<p>### Details
A specially created SVG file that loads by itself and make segmentation fault. Remote attackers can take advantage of this vulnerability to cause a denial of service of the generated SVG file.</p>
<p>It seems that this error affects a lot of websites and causes a generating trash files in ```/tmp``` when uploading this PC file to the server.</p>
<p>I think it's better to check the file descriptor coming from itself before executing ```read()```.</p>
<p>### PoC
1. Generate SVG file:
```&lt;?xml version="1.0" standalone="yes"?&gt;
&lt;!DOCTYPE test&gt;
&lt;svg width="128px" height="128px" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" version="1.1"&gt;
&lt;image height="200" width="200" xlink:href="bad.svg" /&gt;
&lt;/svg&gt;
```
2. Run some commands for verification:
```$rm -f /tmp/*
$./magick --version
Version: ImageMagick 7.1.0-62 Q16-HDRI x86_64 74b3683a4:20230211 https://imagemagick.org
Copyright: (C) 1999 ImageMagick Studio LLC
License: https://imagemagick.org/script/license.php
Features: Cipher DPC HDRI OpenMP(4.5) 
Delegates (built-in): bzlib djvu fontconfig freetype jbig jng jpeg lcms lqr lzma openexr png raqm tiff webp x xml zlib
Compiler: gcc (7.5)
$./magick convert -verbose -font OpenSy…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j96m-mjp6-99xr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-1289</id>
    <title>gsd-2023-1289</title>
    <updated>2026-10-04T09:31:52.231036+00:00</updated>
    <content>gsd-2023-1289</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-1289"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1259</id>
    <title>OESA-2023-1259 — ImageMagick security update</title>
    <updated>2026-10-04T09:31:52.231048+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: ImageMagick, openEuler:20.03-LTS-SP3: ImageMagick, openEuler:22.03-LTS: ImageMagick, openEuler:22.03-LTS-SP1: ImageMagick</p>
<p>Use ImageMagick to create, edit, compose, or convert bitmap images. It can read and write images in a variety of formats (over 200) including PNG, JPEG, GIF, HEIC, TIFF, DPX, EXR, WebP, Postscript, PDF, and SVG. Use ImageMagick to resize, flip, mirror, rotate, distort, shear and transform images, adjust image colors, apply various special effects, or draw text, lines, polygons, ellipses and Bézier curves.

Security Fix(es):

A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a remote attacker to pass a specially crafted SVG file that leads to a segmentation fault, generating many trash files in &amp;quot;/tmp,&amp;quot; resulting in a denial of service. When ImageMagick crashes, it generates a lot of trash files. These trash files can be large if the SVG file contains many render actions. In a denial of service attack, if a remote attacker uploads an SVG file of size t, ImageMagick generates files of size 103*t. If an attacker uploads a 100M SVG, the server will generate about 10G.(CVE-2023-1289)

A heap-based buffer overflow issue was discovered in ImageMagick&amp;apos;s ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.(CVE-2023-1906)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1259"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13263-1</id>
    <title>openSUSE-SU-2024:13263-1 — ImageMagick-7.1.1.17-1.1 on GA media</title>
    <updated>2026-10-04T09:31:52.231083+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ImageMagick-7.1.1.17-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13263-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:1734-1</id>
    <title>SUSE-SU-2023:1734-1 — Security update for ImageMagick</title>
    <updated>2026-10-04T09:31:52.231105+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for ImageMagick</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:1734-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-1289</id>
    <title>UBUNTU-CVE-2023-1289</title>
    <updated>2026-10-04T09:31:52.231119+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: imagemagick, Ubuntu:22.04:LTS: imagemagick, Ubuntu:24.04:LTS: imagemagick</p>
<p>A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a remote attacker to pass a specially crafted SVG file that leads to a segmentation fault, generating many trash files in "/tmp," resulting in a denial of service. When ImageMagick crashes, it generates a lot of trash files. These trash files can be large if the SVG file contains many render actions. In a denial of service attack, if a remote attacker uploads an SVG file of size t, ImageMagick generates files of size 103*t. If an attacker uploads a 100M SVG, the server will generate about 10G.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-1289"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0615</id>
    <title>WID-SEC-W-2023-0615 — ImageMagick: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-04T09:31:52.231143+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in ImageMagick ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0615"/>
  </entry>
</feed>
