Lucene search

K
cveMitreCVE-2006-2440
HistoryMay 18, 2006 - 10:02 a.m.

CVE-2006-2440

2006-05-1810:02:00
mitre
web.nvd.nist.gov
38
cve-2006-2440
heap-based buffer overflow
imagemagick
libmagick
nvd
security vulnerability

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

Low

EPSS

0.012

Percentile

85.5%

Heap-based buffer overflow in the libMagick component of ImageMagick 6.0.6.2 might allow attackers to execute arbitrary code via an image index array that triggers the overflow during filename glob expansion by the ExpandFilenames function.

Affected configurations

Nvd
Node
imagemagickimagemagickMatch6.0.6.2
OR
imagemagickimagemagickMatch6.2.4
VendorProductVersionCPE
imagemagickimagemagick6.0.6.2cpe:2.3:a:imagemagick:imagemagick:6.0.6.2:*:*:*:*:*:*:*
imagemagickimagemagick6.2.4cpe:2.3:a:imagemagick:imagemagick:6.2.4:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

Low

EPSS

0.012

Percentile

85.5%