6.8
CVSSv2

CVE-2008-1096

Published: 05/03/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The load_tile function in the XCF coder in coders/xcf.c in (1) ImageMagick 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote malicious users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .xcf file that triggers an out-of-bounds heap write, possibly related to the ScaleCharToQuantum function.

Vulnerable Product Search on Vulmon Subscribe to Product

imagemagick graphicsmagick 1.1.10

imagemagick graphicsmagick 1.1.11

imagemagick imagemagick 6.2.8.2

imagemagick imagemagick 6.2.8.3

imagemagick graphicsmagick 1.1.12

imagemagick graphicsmagick 1.1.7

imagemagick imagemagick 6.2.8.0

imagemagick imagemagick 6.2.8.1

imagemagick graphicsmagick 1.1.8

imagemagick graphicsmagick 1.1.9

Vendor Advisories

Debian Bug report logs - #414370 graphicsmagick: Couple of segfaults in PICT coder Package: graphicsmagick; Maintainer for graphicsmagick is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Source for graphicsmagick is src:graphicsmagick (PTS, buildd, popcon) Reported by: Sami Liedes <sliedes@cchutfi> Date: Sun, 11 Mar 2 ...
It was discovered that ImageMagick did not correctly handle certain malformed XCF images If a user were tricked into opening a specially crafted image with an application that uses ImageMagick, an attacker could cause a denial of service and possibly execute arbitrary code with the user’s privileges ...
Several vulnerabilities have been discovered in graphicsmagick, a collection of image processing tool, which can lead to the execution of arbitrary code, exposure of sensitive information or cause DoS The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-1667 Multiple integer overflows in XInitImage functi ...
Several vulnerabilities have been discovered in the imagemagick image manipulation programs which can lead to the execution of arbitrary code, exposure of sensitive information or cause DoS The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-1667 Multiple integer overflows in XInitImage function in xwd ...