CVE-2005-0005Improper Restriction of Operations within the Bounds of a Memory Buffer in Imagemagick

8 documents8 sources
Severity
7.5HIGHNVD
EPSS
3.5%
top 12.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 2
Latest updateMay 1

Description

Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages6 packages

Debianimagemagick/imagemagick< 6:6.0.6.2-2.1+3
NVDimagemagick/imagemagick24 versions+23
NVDsgi/propack3.0
NVDgentoo/linux5 versions+4
NVDsuse/suse_linux6 versions+5

Also affects: Debian Linux 3.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-q7qj-9xh3-f579: Heap-based buffer overflow in psd2022-05-01
OSV
CVE-2005-0005: Heap-based buffer overflow in psd2005-05-02
CVEList
CVE-2005-0005: Heap-based buffer overflow in psd2005-01-19

📋Vendor Advisories

3
Ubuntu
imagemagick vulnerability2005-01-19
Red Hat
security flaw2005-01-17
Debian
CVE-2005-0005: imagemagick - Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly e...2005

💬Community

1
Bugzilla
CVE-2005-0005 security flaw2018-08-16
CVE-2005-0005 — Imagemagick vulnerability | cvebase