Lucene search

K
ubuntucveUbuntu.comUB:CVE-2008-1096
HistoryMar 05, 2008 - 12:00 a.m.

CVE-2008-1096

2008-03-0500:00:00
ubuntu.com
ubuntu.com
16

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.043

Percentile

92.5%

The load_tile function in the XCF coder in coders/xcf.c in (1) ImageMagick
6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote
attackers to cause a denial of service (crash) or possibly execute
arbitrary code via a crafted .xcf file that triggers an out-of-bounds heap
write, possibly related to the ScaleCharToQuantum function.

Bugs

Notes

Author Note
jdstrand Debian and Redhat bugs have test cases
OSVersionArchitecturePackageVersionFilename
ubuntu9.04noarchgraphicsmagick<Β 1.1.11-3.2+lenny1build0.9.04.1UNKNOWN
ubuntu9.10noarchgraphicsmagick<Β 1.3.5-5.1UNKNOWN
ubuntu10.04noarchgraphicsmagick<Β 1.3.5-5.1UNKNOWN
ubuntu10.10noarchgraphicsmagick<Β 1.3.5-5.1UNKNOWN
ubuntu11.04noarchgraphicsmagick<Β 1.3.5-5.1UNKNOWN
ubuntu11.10noarchgraphicsmagick<Β 1.3.5-5.1UNKNOWN
ubuntu6.06noarchimagemagick<Β 6:6.2.4.5-0.6ubuntu0.8UNKNOWN
ubuntu7.10noarchimagemagick<Β 7:6.2.4.5.dfsg1-2ubuntu1.1UNKNOWN

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.043

Percentile

92.5%