CVE-2004-0981
published 2005-02-09CVE-2004-0981: Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain image file.
PriorityP433critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.84%
92.4th percentile
Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain image file.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | graphicsmagick | < graphicsmagick 1.1.7-1 (bookworm) | graphicsmagick 1.1.7-1 (bookworm) |
| debian | imagemagick | < graphicsmagick 1.1.7-1 (bookworm) | graphicsmagick 1.1.7-1 (bookworm) |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.7-1 | 1.1.7-1 |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.7-1 | 1.1.7-1 |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.7-1 | 1.1.7-1 |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.7-1 | 1.1.7-1 |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | >= 0 < 6:6.0.6.2-1.5 | 6:6.0.6.2-1.5 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
XML library vulnerabilities
vendor_ubuntu·2004-10-30
CVE-2004-0981 XML library vulnerabilities
Title: XML library vulnerabilities
Summary: XML library vulnerabilities
Several buffer overflows have been discovered in libxml2's FTP connection
and DNS resolution functions. Supplying very long FTP URLs or IP
addresses might result in execution of arbitrary code with the
privileges of the process using libxml2.
Since libxml2 is used in packages like php4-imagick, the vulnerability
also might lead to privilege escalation, like executing attacker
supplied code with a web server's privileges.
However, this does not affect the core XML parsing code, which is what
the majority of programs use this library for.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
imagemagick vulnerability
vendor_ubuntu·2004-10-27
CVE-2004-0981 imagemagick vulnerability
Title: imagemagick vulnerability
Summary: imagemagick vulnerability
A buffer overflow in imagemagick's EXIF parsing routine has been
discovered in imagemagick versions prior to 6.1.0. Trying to query
EXIF information of a malicious image file might result in execution
of arbitrary code with the user's privileges.
Since imagemagick can be used in custom printing systems, this also
might lead to privilege escalation (execute code with the printer
spooler's privileges). However, Ubuntu's standard printing system does
not use imagemagick, thus there is no risk of privilege escalation in
a standard installation.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
security flaw
vendor_redhat·2004-10-06·CVSS 10.0
CVE-2004-0981 [CRITICAL] security flaw
security flaw
Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain image file.
Debian
CVE-2004-0981: graphicsmagick - Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows r...
vendor_debian·2004·CVSS 10.0
CVE-2004-0981 [CRITICAL] CVE-2004-0981: graphicsmagick - Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows r...
Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain image file.
Scope: local
bookworm: resolved (fixed in 1.1.7-1)
bullseye: resolved (fixed in 1.1.7-1)
forky: resolved (fixed in 1.1.7-1)
sid: resolved (fixed in 1.1.7-1)
trixie: resolved (fixed in 1.1.7-1)
GHSA
GHSA-j36p-8jhh-296q: Buffer overflow in the EXIF parsing routine in ImageMagick before 6
ghsa_unreviewed·2022-04-29
CVE-2004-0981 [HIGH] GHSA-j36p-8jhh-296q: Buffer overflow in the EXIF parsing routine in ImageMagick before 6
Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain image file.
OSV
CVE-2004-0981: Buffer overflow in the EXIF parsing routine in ImageMagick before 6
osv·2005-02-09·CVSS 10.0
CVE-2004-0981 [CRITICAL] CVE-2004-0981: Buffer overflow in the EXIF parsing routine in ImageMagick before 6
Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain image file.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/12995/http://security.gentoo.org/glsa/glsa-200411-11.xmlhttp://www.imagemagick.org/www/Changelog.htmlhttp://www.securityfocus.org/bid/11548https://exchange.xforce.ibmcloud.com/vulnerabilities/17903https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10472https://www.ubuntu.com/usn/usn-7-1/http://secunia.com/advisories/12995/http://security.gentoo.org/glsa/glsa-200411-11.xmlhttp://www.imagemagick.org/www/Changelog.htmlhttp://www.securityfocus.org/bid/11548https://exchange.xforce.ibmcloud.com/vulnerabilities/17903https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10472https://www.ubuntu.com/usn/usn-7-1/
2005-02-09
Published