PT-2007-6097 · Imagemagick+1 · Imagemagick+1

Regenrecht

·

Published

2007-09-24

·

Updated

2024-06-15

·

CVE-2007-4985

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 6.3.5-9
Description The issue allows context-dependent attackers to cause a denial of service via a crafted image file. This can trigger an infinite loop in either the ReadDCMImage function, related to ReadBlobByte function calls, or the ReadXCFImage function, related to ReadBlobMSBLong function calls.
Recommendations For versions prior to 6.3.5-9, update to version 6.3.5-9 or later to resolve the issue. As a temporary workaround, consider restricting the processing of image files from untrusted sources to minimize the risk of exploitation.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-4985
DSA-1858-1
DSA-1903-1
DTSA-63-1
OPENSUSE-SU-2024:10596-1
OPENSUSE-SU-2024:10597-1
RHSA-2008:0145
RHSA-2008:0165
RHSA-2008_0145

Affected Products

Imagemagick
Red Hat