CVE-2024-48514

php-heic-to-jpg <= 1.0.5 is vulnerable to code injection (fixed in 1.0.6). An attacker who can upload heic images is able to execute code on the remote server via the file name. As a result, the CIA is no longer guaranteed. This affects php-heic-to-jpg 1.0.5 and below.
Configurations

No configuration.

History

19 Dec 2024, 16:15

Type Values Removed Values Added
References
  • () https://advisories.gitlab.com/pkg/composer/maestroerror/php-heic-to-jpg/CVE-2024-48514/ -
  • () https://github.com/advisories/GHSA-g8v9-c8m3-942v -
Summary (en) php-heic-to-jpg <= 1.0.5 is vulnerable to remote code execution. An attacker who can upload heic images is able to execute code on the remote server via the file name. As a result, the CIA is no longer guaranteed. This affects php-heic-to-jpg 1.0.5 and below. (en) php-heic-to-jpg <= 1.0.5 is vulnerable to code injection (fixed in 1.0.6). An attacker who can upload heic images is able to execute code on the remote server via the file name. As a result, the CIA is no longer guaranteed. This affects php-heic-to-jpg 1.0.5 and below.

21 Nov 2024, 09:40

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-94

25 Oct 2024, 12:56

Type Values Removed Values Added
Summary
  • (es) php-heic-to-jpg &lt;= 1.0.5 es vulnerable a la ejecución remota de código. Un atacante que pueda cargar imágenes heic puede ejecutar código en el servidor remoto a través del nombre del archivo. Como resultado, la CIA ya no está garantizada. Esto afecta a php-heic-to-jpg 1.0.5 y versiones anteriores.

24 Oct 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-24 18:15

Updated : 2024-12-19 16:15


NVD link : CVE-2024-48514

Mitre link : CVE-2024-48514

CVE.ORG link : CVE-2024-48514


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')