PT-2007-6097 · Imagemagick+1 · Imagemagick+1

Regenrecht

·

Publicado

2007-09-24

·

Atualizado

2024-06-15

·

CVE-2007-4985

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 6.3.5-9
Description The issue allows context-dependent attackers to cause a denial of service via a crafted image file. This can trigger an infinite loop in either the ReadDCMImage function, related to ReadBlobByte function calls, or the ReadXCFImage function, related to ReadBlobMSBLong function calls.
Recommendations For versions prior to 6.3.5-9, update to version 6.3.5-9 or later to resolve the issue. As a temporary workaround, consider restricting the processing of image files from untrusted sources to minimize the risk of exploitation.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-4985
DSA-1858-1
DSA-1903-1
DTSA-63-1
OPENSUSE-SU-2024:10596-1
OPENSUSE-SU-2024:10597-1
RHSA-2008:0145
RHSA-2008:0165
RHSA-2008_0145

Produtos afetados

Imagemagick
Red Hat