PT-2005-1460 · Imagemagick+1 · Imagemagick+1

Tavis Ormandy

·

Published

2005-03-07

·

Updated

2017-10-11

·

CVE-2005-0397

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 6.0.2.5
Description A format string issue in the SetImageInfo function in image.c may allow remote attackers to cause an application crash and possibly execute arbitrary code via format string specifiers in a filename argument to convert, which may be called by other web applications.
Recommendations For versions prior to 6.0.2.5, update to version 6.0.2.5 or later to resolve the issue. As a temporary workaround, consider restricting the use of the convert function with untrusted input until a patch is applied. Avoid using the convert function with filenames that contain format string specifiers.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0397
DSA-702-1
RHSA-2005:070
RHSA-2005:320
RHSA-2005_070
RHSA-2005_320

Affected Products

Imagemagick
Red Hat