Lucene search

K
freebsdFreeBSD18E3A5BE-81F9-11DB-95A2-0012F06707F0
HistoryNov 14, 2006 - 12:00 a.m.

ImageMagick -- SGI Image File heap overflow vulnerability

2006-11-1400:00:00
vuxml.freebsd.org
14

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.028

Percentile

90.7%

SecurityFocus reports about ImageMagick:

ImageMagick is prone to a remote heap-based buffer-overflow
vulnerability because the application fails to properly
bounds-check user-supplied input before copying it to an
insufficiently sized memory buffer.
Exploiting this issue allows attackers to execute arbitrary
machine code in the context of applications that use the
ImageMagick library.

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.028

Percentile

90.7%