Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2005-1275

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2005-1275
Last Modified 21 Aug 2010 12:28:23
Published 25 Apr 2005 12:00:00
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2005-1275

Summary

Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a PNM file with a small colors value.

Vulnerable Systems

Application

  • Graphicsmagick 1.0

  • Graphicsmagick 1.0.6

  • Graphicsmagick 1.1

  • Graphicsmagick 1.1.3

  • Graphicsmagick 1.1.4

  • Graphicsmagick 1.1.5

  • Imagemagick 6.0

  • Imagemagick 6.0.1

  • Imagemagick 6.0.2

  • Imagemagick 6.0.2.5

  • Imagemagick 6.0.3

  • Imagemagick 6.0.4

  • Imagemagick 6.0.5

  • Imagemagick 6.0.6

  • Imagemagick 6.0.7

  • Imagemagick 6.0.8

  • Imagemagick 6.1

  • Imagemagick 6.1.1.6

  • Imagemagick 6.1.2

  • Imagemagick 6.1.3

  • Imagemagick 6.1.4

  • Imagemagick 6.1.5

  • Imagemagick 6.1.6

  • Imagemagick 6.1.7

  • Imagemagick 6.1.8

  • Imagemagick 6.2

  • Imagemagick 6.2.0.4

  • Imagemagick 6.2.0.7

  • Imagemagick 6.2.1


References

CONFIRM - http://www.imagemagick.org/script/changelog.php

BID - 13351

MISC - http://www.overflow.pl/adv/imheapoverflow.txt

BUGTRAQ - 20050424 [Overflow.pl] ImageMagick ReadPNMImage() Heap Overflow

MISC - http://bugs.gentoo.org/show_bug.cgi?id=90423

REDHAT - RHSA-2005:413

MANDRAKE - MDKSA-2005:107


Last Updated: 27 May 2016 10:40:06