ImageMagick is a free and open-source software suite, used for editing and manipulating digital images. The `AppImage` version `ImageMagick` might use an empty path when setting `MAGICK_CONFIGURE_PATH` and `LD_LIBRARY_PATH` environment variables while executing, which might lead to arbitrary code execution by loading malicious configuration files or shared libraries in the current working directory while executing `ImageMagick`. The vulnerability is fixed in 7.11-36.

Project Subscriptions

Vendors Products
Imagemagick Subscribe
Imagemagick Subscribe
Linux Kernel Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 20 Nov 2025 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.03348}

epss

{'score': 0.03345}


Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.03715}

epss

{'score': 0.03348}


Wed, 11 Sep 2024 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Imagemagick
Imagemagick imagemagick
CPEs cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Vendors & Products Imagemagick
Imagemagick imagemagick

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T04:46:53.171Z

Reserved: 2024-07-22T13:57:37.137Z

Link: CVE-2024-41817

cve-icon Vulnrichment

Updated: 2024-08-02T04:46:53.171Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-29T16:15:05.360

Modified: 2025-11-20T19:21:58.747

Link: CVE-2024-41817

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-07-27T13:13:00Z

Links: CVE-2024-41817 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses