PT-2005-1460 · Imagemagick+1 · Imagemagick+1

Tavis Ormandy

·

Publicado

2005-03-07

·

Atualizado

2017-10-11

·

CVE-2005-0397

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 6.0.2.5
Description A format string issue in the SetImageInfo function in image.c may allow remote attackers to cause an application crash and possibly execute arbitrary code via format string specifiers in a filename argument to convert, which may be called by other web applications.
Recommendations For versions prior to 6.0.2.5, update to version 6.0.2.5 or later to resolve the issue. As a temporary workaround, consider restricting the use of the convert function with untrusted input until a patch is applied. Avoid using the convert function with filenames that contain format string specifiers.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-0397
DSA-702-1
RHSA-2005:070
RHSA-2005:320
RHSA-2005_070
RHSA-2005_320

Produtos afetados

Imagemagick
Red Hat