Lucene search

K
gentooGentoo FoundationGLSA-200411-11
HistoryNov 06, 2004 - 12:00 a.m.

ImageMagick: EXIF buffer overflow

2004-11-0600:00:00
Gentoo Foundation
security.gentoo.org
15

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.089

Percentile

94.6%

Background

ImageMagick is a collection of tools to read, write and manipulate images in many formats.

Description

ImageMagick fails to do proper bounds checking when handling image files with EXIF information.

Impact

An attacker could use an image file with specially-crafted EXIF information to cause arbitrary code execution with the permissions of the user running ImageMagick.

Workaround

There is no known workaround at this time.

Resolution

All ImageMagick users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=media-gfx/imagemagick-6.1.3.2"
OSVersionArchitecturePackageVersionFilename
Gentooanyallmedia-gfx/imagemagick< 6.1.3.2UNKNOWN

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.089

Percentile

94.6%