6.8
CVSSv2

CVE-2008-1097

Published: 05/03/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx.c in (1) ImageMagick 6.2.4-5 and 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote malicious users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .pcx file that triggers incorrect memory allocation for the scanline array, leading to memory corruption.

Vulnerable Product Search on Vulmon Subscribe to Product

imagemagick graphicsmagick 1.1.9

imagemagick imagemagick 6.2.8.0

imagemagick imagemagick 6.2.8.1

imagemagick graphicsmagick 1.1.10

imagemagick imagemagick 6.2.8.2

imagemagick imagemagick 6.2.8.3

imagemagick graphicsmagick 1.1.7

imagemagick graphicsmagick 1.1.8

imagemagick graphicsmagick 1.1.11

imagemagick graphicsmagick 1.1.12

Vendor Advisories

Several vulnerabilities have been discovered in the imagemagick image manipulation programs which can lead to the execution of arbitrary code, exposure of sensitive information or cause DoS The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-1667 Multiple integer overflows in XInitImage function in xwd ...