AWS Security Advisories · September 2023 — AWS Security Advisories
26 advisories 123 CVEs

Amazon Linux (AL1, AL2, AL2023), AWS Security Bulletins, and AWS SDK CVEs for 2023-09. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALAS-2023-1810

ALAS · AL1Active exploitation (sightings)Medium2023-09-07

ALAS-2023-1810: php54-pecl-imagick (medium)

CVEs:CVE-2017-1000476CVE-2017-11166CVE-2017-12805CVE-2017-12806CVE-2017-18251CVE-2017-18252CVE-2017-18254CVE-2017-18271CVE-2017-18273CVE-2018-10177CVE-2018-10804CVE-2018-10805CVE-2018-11656CVE-2018-12599CVE-2018-12600CVE-2018-13153CVE-2018-14434CVE-2018-14435CVE-2018-14436CVE-2018-14437CVE-2018-15607CVE-2018-16328CVE-2018-16749CVE-2018-16750CVE-2018-18544CVE-2018-20467CVE-2018-8804CVE-2018-9133CVE-2019-10131CVE-2019-10650CVE-2019-11470CVE-2019-11472CVE-2019-11597CVE-2019-11598CVE-2019-12974CVE-2019-12975CVE-2019-12976CVE-2019-12978CVE-2019-12979CVE-2019-13133CVE-2019-13134CVE-2019-13135CVE-2019-13295CVE-2019-13297CVE-2019-13300CVE-2019-13301CVE-2019-13304CVE-2019-13305CVE-2019-13306CVE-2019-13307CVE-2019-13309CVE-2019-13310CVE-2019-13311CVE-2019-13454CVE-2019-14980CVE-2019-14981CVE-2019-15139CVE-2019-15140CVE-2019-15141CVE-2019-16708CVE-2019-16709CVE-2019-16710CVE-2019-16711CVE-2019-16712CVE-2019-16713CVE-2019-17540CVE-2019-17541CVE-2019-19948CVE-2019-19949CVE-2019-7175CVE-2019-7397CVE-2019-7398CVE-2019-9956

Affected products

ProductStatusVendorPackageEcosystem
php54-pecl-imagick affected Amazon php54-pecl-imagick
Upstream advisory

ALAS-2023-1811

ALAS · AL1Active exploitation (sightings)Medium2023-09-07

ALAS-2023-1811: php56-pecl-imagick (medium)

CVEs:CVE-2017-1000476CVE-2017-11166CVE-2017-12805CVE-2017-12806CVE-2017-18251CVE-2017-18252CVE-2017-18254CVE-2017-18271CVE-2017-18273CVE-2018-10177CVE-2018-10804CVE-2018-10805CVE-2018-11656CVE-2018-12599CVE-2018-12600CVE-2018-13153CVE-2018-14434CVE-2018-14435CVE-2018-14436CVE-2018-14437CVE-2018-15607CVE-2018-16328CVE-2018-16749CVE-2018-16750CVE-2018-18544CVE-2018-20467CVE-2018-8804CVE-2018-9133CVE-2019-10131CVE-2019-10650CVE-2019-11470CVE-2019-11472CVE-2019-11597CVE-2019-11598CVE-2019-12974CVE-2019-12975CVE-2019-12976CVE-2019-12978CVE-2019-12979CVE-2019-13133CVE-2019-13134CVE-2019-13135CVE-2019-13295CVE-2019-13297CVE-2019-13300CVE-2019-13301CVE-2019-13304CVE-2019-13305CVE-2019-13306CVE-2019-13307CVE-2019-13309CVE-2019-13310CVE-2019-13311CVE-2019-13454CVE-2019-14980CVE-2019-14981CVE-2019-15139CVE-2019-15140CVE-2019-15141CVE-2019-16708CVE-2019-16709CVE-2019-16710CVE-2019-16711CVE-2019-16712CVE-2019-16713CVE-2019-17540CVE-2019-17541CVE-2019-19948CVE-2019-19949CVE-2019-7175CVE-2019-7397CVE-2019-7398CVE-2019-9956

Affected products

ProductStatusVendorPackageEcosystem
php56-pecl-imagick affected Amazon php56-pecl-imagick
Upstream advisory

ALAS-2023-1812

ALAS · AL1Active exploitation (sightings)Medium2023-09-07

ALAS-2023-1812: php55-pecl-imagick (medium)

CVEs:CVE-2017-1000476CVE-2017-11166CVE-2017-12805CVE-2017-12806CVE-2017-18251CVE-2017-18252CVE-2017-18254CVE-2017-18271CVE-2017-18273CVE-2018-10177CVE-2018-10804CVE-2018-10805CVE-2018-11656CVE-2018-12599CVE-2018-12600CVE-2018-13153CVE-2018-14434CVE-2018-14435CVE-2018-14436CVE-2018-14437CVE-2018-15607CVE-2018-16328CVE-2018-16749CVE-2018-16750CVE-2018-18544CVE-2018-20467CVE-2018-8804CVE-2018-9133CVE-2019-10131CVE-2019-10650CVE-2019-11470CVE-2019-11472CVE-2019-11597CVE-2019-11598CVE-2019-12974CVE-2019-12975CVE-2019-12976CVE-2019-12978CVE-2019-12979CVE-2019-13133CVE-2019-13134CVE-2019-13135CVE-2019-13295CVE-2019-13297CVE-2019-13300CVE-2019-13301CVE-2019-13304CVE-2019-13305CVE-2019-13306CVE-2019-13307CVE-2019-13309CVE-2019-13310CVE-2019-13311CVE-2019-13454CVE-2019-14980CVE-2019-14981CVE-2019-15139CVE-2019-15140CVE-2019-15141CVE-2019-16708CVE-2019-16709CVE-2019-16710CVE-2019-16711CVE-2019-16712CVE-2019-16713CVE-2019-17540CVE-2019-17541CVE-2019-19948CVE-2019-19949CVE-2019-7175CVE-2019-7397CVE-2019-7398CVE-2019-9956

Affected products

ProductStatusVendorPackageEcosystem
php55-pecl-imagick affected Amazon php55-pecl-imagick
Upstream advisory

ALAS-2023-1813

ALAS · AL1Active exploitation (sightings)Medium2023-09-07

ALAS-2023-1813: php70-pecl-imagick (medium)

CVEs:CVE-2017-1000476CVE-2017-11166CVE-2017-12805CVE-2017-12806CVE-2017-18251CVE-2017-18252CVE-2017-18254CVE-2017-18271CVE-2017-18273CVE-2018-10177CVE-2018-10804CVE-2018-10805CVE-2018-11656CVE-2018-12599CVE-2018-12600CVE-2018-13153CVE-2018-14434CVE-2018-14435CVE-2018-14436CVE-2018-14437CVE-2018-15607CVE-2018-16328CVE-2018-16749CVE-2018-16750CVE-2018-18544CVE-2018-20467CVE-2018-8804CVE-2018-9133CVE-2019-10131CVE-2019-10650CVE-2019-11470CVE-2019-11472CVE-2019-11597CVE-2019-11598CVE-2019-12974CVE-2019-12975CVE-2019-12976CVE-2019-12978CVE-2019-12979CVE-2019-13133CVE-2019-13134CVE-2019-13135CVE-2019-13295CVE-2019-13297CVE-2019-13300CVE-2019-13301CVE-2019-13304CVE-2019-13305CVE-2019-13306CVE-2019-13307CVE-2019-13309CVE-2019-13310CVE-2019-13311CVE-2019-13454CVE-2019-14980CVE-2019-14981CVE-2019-15139CVE-2019-15140CVE-2019-15141CVE-2019-16708CVE-2019-16709CVE-2019-16710CVE-2019-16711CVE-2019-16712CVE-2019-16713CVE-2019-17540CVE-2019-17541CVE-2019-19948CVE-2019-19949CVE-2019-7175CVE-2019-7397CVE-2019-7398CVE-2019-9956

Affected products

ProductStatusVendorPackageEcosystem
php70-pecl-imagick affected Amazon php70-pecl-imagick
Upstream advisory

ALAS-2023-1814

ALAS · AL1Active exploitation (sightings)Medium2023-09-07

ALAS-2023-1814: php71-pecl-imagick (medium)

CVEs:CVE-2017-1000476CVE-2017-11166CVE-2017-12805CVE-2017-12806CVE-2017-18251CVE-2017-18252CVE-2017-18254CVE-2017-18271CVE-2017-18273CVE-2018-10177CVE-2018-10804CVE-2018-10805CVE-2018-11656CVE-2018-12599CVE-2018-12600CVE-2018-13153CVE-2018-14434CVE-2018-14435CVE-2018-14436CVE-2018-14437CVE-2018-15607CVE-2018-16328CVE-2018-16749CVE-2018-16750CVE-2018-18544CVE-2018-20467CVE-2018-8804CVE-2018-9133CVE-2019-10131CVE-2019-10650CVE-2019-11470CVE-2019-11472CVE-2019-11597CVE-2019-11598CVE-2019-12974CVE-2019-12975CVE-2019-12976CVE-2019-12978CVE-2019-12979CVE-2019-13133CVE-2019-13134CVE-2019-13135CVE-2019-13295CVE-2019-13297CVE-2019-13300CVE-2019-13301CVE-2019-13304CVE-2019-13305CVE-2019-13306CVE-2019-13307CVE-2019-13309CVE-2019-13310CVE-2019-13311CVE-2019-13454CVE-2019-14980CVE-2019-14981CVE-2019-15139CVE-2019-15140CVE-2019-15141CVE-2019-16708CVE-2019-16709CVE-2019-16710CVE-2019-16711CVE-2019-16712CVE-2019-16713CVE-2019-17540CVE-2019-17541CVE-2019-19948CVE-2019-19949CVE-2019-7175CVE-2019-7397CVE-2019-7398CVE-2019-9956

Affected products

ProductStatusVendorPackageEcosystem
php71-pecl-imagick affected Amazon php71-pecl-imagick
Upstream advisory

ALAS-2023-1815

ALAS · AL1Active exploitation (sightings)Medium2023-09-07

ALAS-2023-1815: php72-pecl-imagick (medium)

CVEs:CVE-2017-1000476CVE-2017-11166CVE-2017-12805CVE-2017-12806CVE-2017-18251CVE-2017-18252CVE-2017-18254CVE-2017-18271CVE-2017-18273CVE-2018-10177CVE-2018-10804CVE-2018-10805CVE-2018-11656CVE-2018-12599CVE-2018-12600CVE-2018-13153CVE-2018-14434CVE-2018-14435CVE-2018-14436CVE-2018-14437CVE-2018-15607CVE-2018-16328CVE-2018-16749CVE-2018-16750CVE-2018-18544CVE-2018-20467CVE-2018-8804CVE-2018-9133CVE-2019-10131CVE-2019-10650CVE-2019-11470CVE-2019-11472CVE-2019-11597CVE-2019-11598CVE-2019-12974CVE-2019-12975CVE-2019-12976CVE-2019-12978CVE-2019-12979CVE-2019-13133CVE-2019-13134CVE-2019-13135CVE-2019-13295CVE-2019-13297CVE-2019-13300CVE-2019-13301CVE-2019-13304CVE-2019-13305CVE-2019-13306CVE-2019-13307CVE-2019-13309CVE-2019-13310CVE-2019-13311CVE-2019-13454CVE-2019-14980CVE-2019-14981CVE-2019-15139CVE-2019-15140CVE-2019-15141CVE-2019-16708CVE-2019-16709CVE-2019-16710CVE-2019-16711CVE-2019-16712CVE-2019-16713CVE-2019-17540CVE-2019-17541CVE-2019-19948CVE-2019-19949CVE-2019-7175CVE-2019-7397CVE-2019-7398CVE-2019-9956

Affected products

ProductStatusVendorPackageEcosystem
php72-pecl-imagick affected Amazon php72-pecl-imagick
Upstream advisory

ALAS-2023-1835

ALAS · AL1Active exploitation (sightings)Important2023-09-25

ALAS-2023-1835: ghostscript (important)

CVEs:CVE-2020-21890

Affected products

ProductStatusVendorPackageEcosystem
ghostscript affected Amazon ghostscript
Upstream advisory

ALAS-2023-1823

ALAS · AL1Active exploitation (sightings)Medium2023-09-07

ALAS-2023-1823: poppler (medium)

CVEs:CVE-2020-18839

Affected products

ProductStatusVendorPackageEcosystem
poppler affected Amazon poppler
Upstream advisory

ALAS-2023-1816

ALAS · AL1PoC exploitImportant2023-09-07

ALAS-2023-1816: python38 (important)

CVEs:CVE-2023-40217

Affected products

ProductStatusVendorPackageEcosystem
python38 affected Amazon python38
Upstream advisory

ALAS-2023-1817

ALAS · AL1PoC exploitImportant2023-09-07

ALAS-2023-1817: ca-certificates (important)

CVEs:CVE-2023-37920

Affected products

ProductStatusVendorPackageEcosystem
ca-certificates affected Amazon ca-certificates
Upstream advisory

ALAS-2023-1831

ALAS · AL1Coalition ESS < 30%Medium2023-09-25

ALAS-2023-1831: ImageMagick (medium)

CVEs:CVE-2022-48541

Affected products

ProductStatusVendorPackageEcosystem
ImageMagick affected Amazon ImageMagick
Upstream advisory

ALAS-2023-1820

ALAS · AL1Coalition ESS < 30%Important2023-09-07

ALAS-2023-1820: clamav (important)

CVEs:CVE-2023-20197

Affected products

ProductStatusVendorPackageEcosystem
clamav affected Amazon clamav
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.