OSVDB ID: 28205

Title: ImageMagick XCF Image Decoder Overflow

Info

Disclosure

Aug 24, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

ImageMagick contains a flaw that may allow stack-based and a heap-based overflow. The issue is triggered due to errors within the XCF image decoder when processing specially crafted XCF image files. It is possible that the flaw may allow remote arbitrary code execution resulting in a loss of integrity.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Unknown
Disclosure: OSVDB Verified

Solution

Upgrade to version 6.2.9-1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

ImageMagick Studio LLC

ImageMagick

4.2.9
5.5.7
6.2.3-6
6.2.4-6
6.2.5-5
6.2.6-8
6.2.7-8
6.2.8-8

References

Credit

  • Tavis Ormandy - tavisogoogle.com - Google Information Security Team


Direct URL: http://osvdb.org/28205