CVE-2004-0827

8 documents8 sources
Severity
7.5HIGH
EPSS
3.7%
top 12.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 16
Latest updateApr 29

Description

Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via malformed (1) AVI, (2) BMP, or (3) DIB files.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages13 packages

Debianimagemagick< 5:6.0.7.1-1+3
NVDimagemagick/imagemagick10 versions+9
NVDconectiva/linux10.0, 9.0+1
NVDsuse/suse_linux6 versions+5
NVDredhat/fedora_corecore_1.0, core_2.0, core_3.0+2

Also affects: Ubuntu Linux 4.1, Enterprise Linux 2.1, 3.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-vvxj-99jx-9x48: Multiple buffer overflows in the ImageMagick graphics library 52022-04-29
CVEList
CVE-2004-0827: Multiple buffer overflows in the ImageMagick graphics library 52004-09-24
OSV
CVE-2004-0827: Multiple buffer overflows in the ImageMagick graphics library 52004-09-16

📋Vendor Advisories

3
Ubuntu
imagemagick vulnerabilities2004-12-01
Red Hat
security flaw2004-08-24
Debian
CVE-2004-0827: imagemagick - Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, ...2004

💬Community

1
Bugzilla
CVE-2004-0827 security flaw2018-08-16
CVE-2004-0827 (HIGH CVSS 7.5) | Multiple buffer overflows in the Im | cvebase.io