LWN.net Logo

ImageMagick: buffer overflows

Package(s):ImageMagick CVE #(s):CVE-2006-5456
Created:October 31, 2006 Updated:March 8, 2007
Description: Multiple buffer overflows in GraphicsMagick before 1.1.7 and ImageMagick 6.0.7 allow user-assisted attackers to cause a denial of service and possibly execute execute arbitrary code via (1) a DCM image that is not properly handled by the ReadDCMImage function in coders/dcm.c, or (2) a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c.
Alerts:
Slackware SSA:2007-066-06 2007-03-08
rPath rPSA-2007-0029-1 2007-02-08
rPath rPSA-2006-0218-1 2006-11-27
Gentoo 200611-19 2006-11-24
Fedora FEDORA-2006-1285 2006-11-22
Fedora FEDORA-2006-1286 2006-11-22
Debian DSA-1213-1 2006-11-19
SuSE SUSE-SA:2006:066 2006-11-14
Gentoo 200611-07 2006-11-13
Ubuntu USN-372-1 2006-11-01
Mandriva MDKSA-2006:193 2006-10-30

(Log in to post comments)

ImageMagick: buffer overflows

Posted Nov 3, 2006 0:58 UTC (Fri) by nix (subscriber, #2304) [Link]

Passing odd: the description talks about ImageMagick 6.0.7, but the
details show new versions of every ImageMagick up to 6.2.9.

ImageMagick: buffer overflows

Posted Mar 15, 2007 8:31 UTC (Thu) by mjcox@redhat.com (subscriber, #31775) [Link]

Was fixed in Red Hat Enterprise Linux 4, 3, 2.1 by RHSA-2007:0015

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds