Lucene search

K
ubuntuUbuntuUSN-340-1
HistorySep 06, 2006 - 12:00 a.m.

imagemagick vulnerabilities

2006-09-0600:00:00
ubuntu.com
41

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

Low

EPSS

0.023

Percentile

89.7%

Releases

  • Ubuntu 6.06
  • Ubuntu 5.10
  • Ubuntu 5.04

Details

Tavis Ormandy discovered several buffer overflows in imagemagick’s Sun
Raster and XCF (Gimp) image decoders. By tricking a user or automated
system into processing a specially crafted image, this could be
exploited to execute arbitrary code with the users’ privileges.

OSVersionArchitecturePackageVersionFilename
Ubuntu6.06noarchlibmagick9< 6:6.2.4.5-0.6ubuntu0.2UNKNOWN
Ubuntu5.10noarchlibmagick6< 6:6.2.3.4-1ubuntu1.3UNKNOWN
Ubuntu5.04noarchlibmagick6< 6:6.0.6.2-2.1ubuntu1.4UNKNOWN

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

Low

EPSS

0.023

Percentile

89.7%