PT-2008-2694 · Imagemagick+2 · Imagemagick+2

Publicado

2008-03-05

·

Atualizado

2024-06-15

·

CVE-2008-1096

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ImageMagick version 6.2.8-0 GraphicsMagick version 1.1.7
Description The issue allows user-assisted remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted file. This is related to an out-of-bounds heap write in the load tile function, possibly connected to the ScaleCharToQuantum function.
Recommendations For ImageMagick version 6.2.8-0, consider disabling the load tile function in the XCF coder until a patch is available. For GraphicsMagick version 1.1.7, restrict access to the XCF coder to minimize the risk of exploitation.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-1096
DSA-1858-1
DSA-1903-1
OPENSUSE-SU-2024:10596-1
RHSA-2008:0145
RHSA-2008_0145

Produtos afetados

Graphicsmagick
Imagemagick
Red Hat