In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG.
References
Configurations
Information
Published : 2020-03-18 19:15
Updated : 2021-07-21 11:39
NVD link : CVE-2019-12921
Mitre link : CVE-2019-12921
JSON object : View
Products Affected
graphicsmagick
- graphicsmagick
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
