Lucene search

K
nvd[email protected]NVD:CVE-2008-1097
HistoryMar 05, 2008 - 8:44 p.m.

CVE-2008-1097

2008-03-0520:44:00
CWE-399
web.nvd.nist.gov
6

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

8.2

Confidence

High

EPSS

0.022

Percentile

89.5%

Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx.c in (1) ImageMagick 6.2.4-5 and 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .pcx file that triggers incorrect memory allocation for the scanline array, leading to memory corruption.

Affected configurations

Nvd
Node
imagemagickgraphicsmagickMatch1.1.7
OR
imagemagickgraphicsmagickMatch1.1.8
OR
imagemagickgraphicsmagickMatch1.1.9
OR
imagemagickgraphicsmagickMatch1.1.10
OR
imagemagickgraphicsmagickMatch1.1.11
OR
imagemagickgraphicsmagickMatch1.1.12
OR
imagemagickimagemagickMatch6.2.8.0
OR
imagemagickimagemagickMatch6.2.8.1
OR
imagemagickimagemagickMatch6.2.8.2
OR
imagemagickimagemagickMatch6.2.8.3

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

8.2

Confidence

High

EPSS

0.022

Percentile

89.5%