PT-2008-2695 · Imagemagick+2 · Imagemagick+2

Published

2008-03-05

·

Updated

2024-06-15

·

CVE-2008-1097

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ImageMagick versions 6.2.4-5 through 6.2.8-0 GraphicsMagick version 1.1.7
Description The issue is related to a heap-based buffer overflow in the ReadPCXImage function within the PCX coder. This can be triggered by a crafted .pcx file, leading to incorrect memory allocation for the scanline array and resulting in memory corruption. This could cause a denial of service or potentially allow the execution of arbitrary code.
Recommendations For ImageMagick versions 6.2.4-5 through 6.2.8-0, update to a version that fixes the issue in the ReadPCXImage function. For GraphicsMagick version 1.1.7, update to a version that fixes the issue in the ReadPCXImage function. As a temporary workaround, consider disabling the use of the PCX coder in affected versions until a patch is available.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-1097
DSA-1858-1
OPENSUSE-SU-2024:10596-1
RHSA-2008:0145
RHSA-2008:0165
RHSA-2008_0145

Affected Products

Graphicsmagick
Imagemagick
Red Hat