PT-2008-2694 · Imagemagick+2 · Imagemagick+2

Published

2008-03-05

·

Updated

2024-06-15

·

CVE-2008-1096

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ImageMagick version 6.2.8-0 GraphicsMagick version 1.1.7
Description The issue allows user-assisted remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted file. This is related to an out-of-bounds heap write in the load tile function, possibly connected to the ScaleCharToQuantum function.
Recommendations For ImageMagick version 6.2.8-0, consider disabling the load tile function in the XCF coder until a patch is available. For GraphicsMagick version 1.1.7, restrict access to the XCF coder to minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-1096
DSA-1858-1
DSA-1903-1
OPENSUSE-SU-2024:10596-1
RHSA-2008:0145
RHSA-2008_0145

Affected Products

Graphicsmagick
Imagemagick
Red Hat