Lucene search

K
cve[email protected]CVE-2006-0082
HistoryJan 04, 2006 - 11:03 p.m.

CVE-2006-0082

2006-01-0423:03:00
CWE-134
web.nvd.nist.gov
33
cve-2006-0082
imagemagick
graphicsmagick
format string vulnerability
denial of service
code execution
user-assisted attackers
nvd

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

7.1

Confidence

Low

EPSS

0.066

Percentile

93.8%

Format string vulnerability in the SetImageInfo function in image.c for ImageMagick 6.2.3 and other versions, and GraphicsMagick, allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a numeric format string specifier such as %d in the file name, a variant of CVE-2005-0397, and as demonstrated using the convert program.

Affected configurations

NVD
Node
imagemagickimagemagickMatch6.2.3
VendorProductVersionCPE
imagemagickimagemagick6.2.3cpe:/a:imagemagick:imagemagick:6.2.3:::

References

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

7.1

Confidence

Low

EPSS

0.066

Percentile

93.8%