CVE-2021-39212

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-39212
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-39212.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-39212
Downstream
Related
  • GHSA-qvhr-jj4p-j2qr
Published
2021-09-13T18:15:23Z
Modified
2025-10-14T18:36:54.702670Z
Severity
  • 3.6 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

ImageMagick is free software delivered as a ready-to-run binary distribution or as source code that you may use, copy, modify, and distribute in both open and proprietary applications. In affected versions and in certain cases, Postscript files could be read and written when specifically excluded by a module policy in policy.xml. ex. <policy domain="module" rights="none" pattern="PS" />. The issue has been resolved in ImageMagick 7.1.0-7 and in 6.9.12-22. Fortunately, in the wild, few users utilize the module policy and instead use the coder policy that is also our workaround recommendation: <policy domain="coder" rights="none" pattern="{PS,EPI,EPS,EPSF,EPSI}" />.

References

Affected packages

Git / github.com/imagemagick/imagemagick6

Affected ranges

Type
GIT
Repo
https://github.com/imagemagick/imagemagick6
Events
Type
GIT
Repo
https://github.com/imagemagick/imagemagick
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

6.*

6.9.12-0
6.9.12-1
6.9.12-10
6.9.12-11
6.9.12-12
6.9.12-14
6.9.12-15
6.9.12-16
6.9.12-17
6.9.12-18
6.9.12-19
6.9.12-2
6.9.12-20
6.9.12-21
6.9.12-3
6.9.12-4
6.9.12-5
6.9.12-6
6.9.12-7
6.9.12-8
6.9.12-9

7.*

7.0.1-0
7.0.1-1
7.0.1-10
7.0.1-2
7.0.1-3
7.0.1-4
7.0.1-5
7.0.1-6
7.0.1-7
7.0.1-8
7.0.1-9
7.0.10-0
7.0.10-1
7.0.10-10
7.0.10-11
7.0.10-12
7.0.10-13
7.0.10-14
7.0.10-15
7.0.10-16
7.0.10-17
7.0.10-18
7.0.10-19
7.0.10-2
7.0.10-20
7.0.10-21
7.0.10-22
7.0.10-23
7.0.10-24
7.0.10-25
7.0.10-26
7.0.10-27
7.0.10-28
7.0.10-29
7.0.10-3
7.0.10-30
7.0.10-31
7.0.10-32
7.0.10-33
7.0.10-34
7.0.10-35
7.0.10-36
7.0.10-37
7.0.10-38
7.0.10-39
7.0.10-4
7.0.10-40
7.0.10-41
7.0.10-42
7.0.10-43
7.0.10-44
7.0.10-45
7.0.10-46
7.0.10-47
7.0.10-48
7.0.10-49
7.0.10-5
7.0.10-50
7.0.10-51
7.0.10-52
7.0.10-53
7.0.10-54
7.0.10-55
7.0.10-56
7.0.10-57
7.0.10-58
7.0.10-59
7.0.10-6
7.0.10-60
7.0.10-61
7.0.10-62
7.0.10-7
7.0.10-8
7.0.10-9
7.0.11-0
7.0.11-1
7.0.11-10
7.0.11-11
7.0.11-12
7.0.11-13
7.0.11-14
7.0.11-2
7.0.11-3
7.0.11-4
7.0.11-5
7.0.11-6
7.0.11-7
7.0.11-8
7.0.11-9
7.0.2-0
7.0.2-1
7.0.2-10
7.0.2-2
7.0.2-3
7.0.2-4
7.0.2-5
7.0.2-6
7.0.2-7
7.0.2-8
7.0.2-9
7.0.3-0
7.0.3-1
7.0.3-10
7.0.3-2
7.0.3-3
7.0.3-4
7.0.3-5
7.0.3-6
7.0.3-7
7.0.3-8
7.0.3-9
7.0.4-0
7.0.4-1
7.0.4-10
7.0.4-2
7.0.4-3
7.0.4-4
7.0.4-5
7.0.4-6
7.0.4-7
7.0.4-8
7.0.4-9
7.0.5-0
7.0.5-1
7.0.5-10
7.0.5-2
7.0.5-3
7.0.5-4
7.0.5-5
7.0.5-6
7.0.5-7
7.0.5-8
7.0.5-9
7.0.6-0
7.0.6-1
7.0.6-2
7.0.6-3
7.0.6-4
7.0.6-5
7.0.6-6
7.0.6-7
7.0.6-8
7.0.6-9
7.0.7-0
7.0.7-1
7.0.7-10
7.0.7-11
7.0.7-12
7.0.7-13
7.0.7-14
7.0.7-15
7.0.7-16
7.0.7-17
7.0.7-18
7.0.7-19
7.0.7-2
7.0.7-20
7.0.7-21
7.0.7-22
7.0.7-23
7.0.7-24
7.0.7-25
7.0.7-26
7.0.7-27
7.0.7-28
7.0.7-29
7.0.7-3
7.0.7-30
7.0.7-31
7.0.7-32
7.0.7-33
7.0.7-34
7.0.7-35
7.0.7-36
7.0.7-37
7.0.7-38
7.0.7-39
7.0.7-4
7.0.7-5
7.0.7-6
7.0.7-8
7.0.7-9
7.0.7.7
7.0.8-0
7.0.8-1
7.0.8-10
7.0.8-11
7.0.8-12
7.0.8-13
7.0.8-14
7.0.8-15
7.0.8-16
7.0.8-17
7.0.8-18
7.0.8-19
7.0.8-2
7.0.8-20
7.0.8-21
7.0.8-22
7.0.8-23
7.0.8-24
7.0.8-25
7.0.8-26
7.0.8-27
7.0.8-28
7.0.8-29
7.0.8-3
7.0.8-30
7.0.8-31
7.0.8-32
7.0.8-33
7.0.8-34
7.0.8-35
7.0.8-36
7.0.8-37
7.0.8-38
7.0.8-39
7.0.8-4
7.0.8-40
7.0.8-41
7.0.8-42
7.0.8-43
7.0.8-44
7.0.8-45
7.0.8-46
7.0.8-47
7.0.8-48
7.0.8-49
7.0.8-5
7.0.8-50
7.0.8-51
7.0.8-52
7.0.8-53
7.0.8-54
7.0.8-55
7.0.8-56
7.0.8-57
7.0.8-58
7.0.8-59
7.0.8-6
7.0.8-60
7.0.8-61
7.0.8-62
7.0.8-63
7.0.8-64
7.0.8-65
7.0.8-66
7.0.8-67
7.0.8-68
7.0.8-7
7.0.8-8
7.0.8-9
7.0.9-0
7.0.9-1
7.0.9-10
7.0.9-11
7.0.9-12
7.0.9-13
7.0.9-14
7.0.9-15
7.0.9-16
7.0.9-17
7.0.9-18
7.0.9-19
7.0.9-2
7.0.9-20
7.0.9-21
7.0.9-22
7.0.9-23
7.0.9-24
7.0.9-25
7.0.9-26
7.0.9-27
7.0.9-4
7.0.9-5
7.0.9-6
7.0.9-7
7.0.9-8
7.0.9-9
7.1.0-0
7.1.0-1
7.1.0-2
7.1.0-3
7.1.0-4
7.1.0-5
7.1.0-6

Database specific

{
    "vanir_signatures": [
        {
            "signature_version": "v1",
            "signature_type": "Function",
            "target": {
                "file": "MagickCore/module.c",
                "function": "OpenModule"
            },
            "id": "CVE-2021-39212-04dc5f63",
            "digest": {
                "length": 2905.0,
                "function_hash": "12238449736761196515031936875479012387"
            },
            "deprecated": false,
            "source": "https://github.com/imagemagick/imagemagick/commit/01faddbe2711a4156180c4a92837e2f23683cc68"
        },
        {
            "signature_version": "v1",
            "signature_type": "Function",
            "target": {
                "file": "MagickCore/static.c",
                "function": "RegisterStaticModule"
            },
            "id": "CVE-2021-39212-0b85e734",
            "digest": {
                "length": 1006.0,
                "function_hash": "67095356107172339824823189294631296075"
            },
            "deprecated": false,
            "source": "https://github.com/imagemagick/imagemagick/commit/01faddbe2711a4156180c4a92837e2f23683cc68"
        },
        {
            "signature_version": "v1",
            "signature_type": "Function",
            "target": {
                "file": "MagickCore/static.c",
                "function": "RegisterStaticModules"
            },
            "id": "CVE-2021-39212-15063b98",
            "digest": {
                "length": 340.0,
                "function_hash": "63184281936401086415764659830330242614"
            },
            "deprecated": false,
            "source": "https://github.com/imagemagick/imagemagick/commit/35893e7cad78ce461fcaffa56076c11700ba5e4e"
        },
        {
            "signature_version": "v1",
            "signature_type": "Line",
            "target": {
                "file": "MagickCore/static.c"
            },
            "id": "CVE-2021-39212-2072cbb5",
            "digest": {
                "line_hashes": [
                    "161464366672841640020134010124046521125",
                    "141124472193983977625269801785118258958",
                    "108384596060519357535447944241695217562",
                    "258487691776336968100862765079916223456",
                    "300445242840738940326003630090652496207",
                    "128011902388511518635140373616336014026",
                    "337347454748691601147186908323491545453",
                    "189367590195091707552102665792907139679",
                    "155710556456592442496631619759592383630",
                    "304332711289379008620794157727308316472",
                    "331979865129936986560897612424316949167",
                    "34546885671303321050632682220954312100",
                    "110838583415941214689987570908988952029",
                    "257911632806818842092921089726261664180",
                    "111999203320345666450405824794171170173",
                    "178779667790122642458319338983813196752",
                    "289186773550883895490816465232127853066",
                    "53163241543973580188531734443580948703"
                ],
                "threshold": 0.9
            },
            "deprecated": false,
            "source": "https://github.com/imagemagick/imagemagick/commit/01faddbe2711a4156180c4a92837e2f23683cc68"
        },
        {
            "signature_version": "v1",
            "signature_type": "Function",
            "target": {
                "file": "MagickCore/static.c",
                "function": "RegisterStaticModules"
            },
            "id": "CVE-2021-39212-3d436bd8",
            "digest": {
                "length": 456.0,
                "function_hash": "320567952468272600299621521938514478978"
            },
            "deprecated": false,
            "source": "https://github.com/imagemagick/imagemagick/commit/01faddbe2711a4156180c4a92837e2f23683cc68"
        },
        {
            "signature_version": "v1",
            "signature_type": "Line",
            "target": {
                "file": "MagickCore/module.c"
            },
            "id": "CVE-2021-39212-4a389505",
            "digest": {
                "line_hashes": [
                    "161464366672841640020134010124046521125",
                    "141124472193983977625269801785118258958",
                    "108384596060519357535447944241695217562",
                    "258487691776336968100862765079916223456"
                ],
                "threshold": 0.9
            },
            "deprecated": false,
            "source": "https://github.com/imagemagick/imagemagick/commit/01faddbe2711a4156180c4a92837e2f23683cc68"
        },
        {
            "signature_version": "v1",
            "signature_type": "Function",
            "target": {
                "file": "MagickCore/static.c",
                "function": "RegisterStaticModule"
            },
            "id": "CVE-2021-39212-8dc9fb9e",
            "digest": {
                "length": 1007.0,
                "function_hash": "3555650037291524282550641662791173921"
            },
            "deprecated": false,
            "source": "https://github.com/imagemagick/imagemagick/commit/35893e7cad78ce461fcaffa56076c11700ba5e4e"
        },
        {
            "signature_version": "v1",
            "signature_type": "Line",
            "target": {
                "file": "MagickCore/static.c"
            },
            "id": "CVE-2021-39212-e86239b7",
            "digest": {
                "line_hashes": [
                    "245617195997029489383654427104549917156",
                    "55780723640404020164828960750440420480",
                    "226170224069707727205190332989032059380",
                    "131025510662049958977924086546334637515",
                    "257911632806818842092921089726261664180",
                    "143619803033248316394314000302212847363",
                    "31835007959196602870548180955827925933",
                    "302653041741808141148766325054036889142"
                ],
                "threshold": 0.9
            },
            "deprecated": false,
            "source": "https://github.com/imagemagick/imagemagick/commit/35893e7cad78ce461fcaffa56076c11700ba5e4e"
        }
    ]
}