PT-2003-1707 · Imagemagick · Imagemagick
Angelo Rosiello
·
Published
2003-07-15
·
Updated
2016-10-18
·
CVE-2003-0555
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
ImageMagick versions 5.4.3.x and earlier
Description:
The issue allows attackers to cause a denial of service, potentially leading to a crash, and may also enable the execution of arbitrary code. This is achieved through the use of a filename containing
%x, which could trigger a format string vulnerability.Recommendations:
For versions 5.4.3.x and earlier, update to a version that fixes this issue to prevent potential denial of service and arbitrary code execution.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Imagemagick