CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
Percentile
93.2%
Integer overflow in the XMakeImage function in magick/xwindow.c in
ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a
denial of service (crash) and possibly execute arbitrary code via a crafted
TIFF file, which triggers a buffer overflow. NOTE: some of these details
are obtained from third party information.
Author | Note |
---|---|
jdstrand | patch is from svn commit r513 in trunk (but has extra stuff that is unrelated) |
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 9.04 | noarch | graphicsmagick | < 1.1.11-3.2+lenny1build0.9.04.1 | UNKNOWN |
ubuntu | 6.06 | noarch | imagemagick | < 6:6.2.4.5-0.6ubuntu0.9 | UNKNOWN |
ubuntu | 8.04 | noarch | imagemagick | < 7:6.3.7.9.dfsg1-2ubuntu1.1 | UNKNOWN |
ubuntu | 8.10 | noarch | imagemagick | < 7:6.3.7.9.dfsg1-2ubuntu3.1 | UNKNOWN |
ubuntu | 9.04 | noarch | imagemagick | < 7:6.4.5.4.dfsg1-1ubuntu3.1 | UNKNOWN |
ubuntu | 9.10 | noarch | imagemagick | < 7:6.4.5.4.dfsg1-1ubuntu4 | UNKNOWN |
ubuntu | 10.04 | noarch | imagemagick | < 7:6.4.5.4.dfsg1-1ubuntu4 | UNKNOWN |
ubuntu | 10.10 | noarch | imagemagick | < 7:6.4.5.4.dfsg1-1ubuntu4 | UNKNOWN |
ubuntu | 11.04 | noarch | imagemagick | < 7:6.4.5.4.dfsg1-1ubuntu4 | UNKNOWN |
ubuntu | 11.10 | noarch | imagemagick | < 7:6.4.5.4.dfsg1-1ubuntu4 | UNKNOWN |