PT-2003-1707 · Imagemagick · Imagemagick

Angelo Rosiello

·

Published

2003-07-15

·

Updated

2016-10-18

·

CVE-2003-0555

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: ImageMagick versions 5.4.3.x and earlier
Description: The issue allows attackers to cause a denial of service, potentially leading to a crash, and may also enable the execution of arbitrary code. This is achieved through the use of a filename containing %x, which could trigger a format string vulnerability.
Recommendations: For versions 5.4.3.x and earlier, update to a version that fixes this issue to prevent potential denial of service and arbitrary code execution.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0555

Affected Products

Imagemagick