OSVDB ID: 28204

Title: ImageMagick sun.c Multiple Function Rasterfile Processing Overflow

Info

Disclosure

Aug 24, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

ImageMagick contains a flaw that may allow heap-based buffer overflows. The issue is triggered due to unspecified errors within the 'DecodeBitmap()' function and the 'ReadSUNImage()' function in sun.c when processing specially crafted Sun Rasterfile images. It is possible that the flaw may allow remote arbitrary code execution resulting in a loss of integrity.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Unknown
Disclosure: OSVDB Verified

Solution

Upgrade to version 6.2.9-1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

ImageMagick Studio LLC

ImageMagick

4.2.9
5.5.7
6.2.3-6
6.2.4-6
6.2.5-5
6.2.6-8
6.2.7-8
6.2.8-8

References

Credit

  • Tavis Ormandy - tavisogoogle.com - Google Information Security Team


Direct URL: http://osvdb.org/28204