CVE-2005-0397
published 2005-05-02CVE-2005-0397: Format string vulnerability in the SetImageInfo function in image.c for ImageMagick before 6.0.2.5 may allow remote attackers to cause a denial of service…
PriorityP428high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.22%
89.9th percentile
Format string vulnerability in the SetImageInfo function in image.c for ImageMagick before 6.0.2.5 may allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a filename argument to convert, which may be called by other web applications.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | graphicsmagick | < graphicsmagick 1.1.7-1 (bookworm) | graphicsmagick 1.1.7-1 (bookworm) |
| debian | imagemagick | < graphicsmagick 1.1.7-1 (bookworm) | graphicsmagick 1.1.7-1 (bookworm) |
| debian | imagemagick | < imagemagick 6:6.2.4.5-0.6 (bookworm) | imagemagick 6:6.2.4.5-0.6 (bookworm) |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.7-1 | 1.1.7-1 |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.7-1 | 1.1.7-1 |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.7-1 | 1.1.7-1 |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.7-1 | 1.1.7-1 |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | >= 0 < 6:6.0.6.2-2.2 | 6:6.0.6.2-2.2 |
| imagemagick | imagemagick | >= 0 < 6:6.2.4.5-0.6 | 6:6.2.4.5-0.6 |
| imagemagick | imagemagick | >= 0 < 6:6.0.6.2-2.2 | 6:6.0.6.2-2.2 |
| imagemagick | imagemagick | >= 0 < 6:6.2.4.5-0.6 | 6:6.2.4.5-0.6 |
| imagemagick | imagemagick | >= 0 < 6:6.0.6.2-2.2 | 6:6.0.6.2-2.2 |
| imagemagick | imagemagick | >= 0 < 6:6.2.4.5-0.6 | 6:6.2.4.5-0.6 |
| imagemagick | imagemagick | >= 0 < 6:6.0.6.2-2.2 | 6:6.0.6.2-2.2 |
| imagemagick | imagemagick | >= 0 < 6:6.2.4.5-0.6 | 6:6.2.4.5-0.6 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gqwr-p67x-5fff: Format string vulnerability in the SetImageInfo function in image
ghsa_unreviewed·2022-05-03·CVSS 7.5
CVE-2006-0082 [HIGH] CWE-134 GHSA-gqwr-p67x-5fff: Format string vulnerability in the SetImageInfo function in image
Format string vulnerability in the SetImageInfo function in image.c for ImageMagick 6.2.3 and other versions, and GraphicsMagick, allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a numeric format string specifier such as %d in the file name, a variant of CVE-2005-0397, and as demonstrated using the convert program.
GHSA
GHSA-9qw2-jqcg-348f: Format string vulnerability in the SetImageInfo function in image
ghsa_unreviewed·2022-05-01
CVE-2005-0397 [HIGH] GHSA-9qw2-jqcg-348f: Format string vulnerability in the SetImageInfo function in image
Format string vulnerability in the SetImageInfo function in image.c for ImageMagick before 6.0.2.5 may allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a filename argument to convert, which may be called by other web applications.
OSV
CVE-2006-0082: Format string vulnerability in the SetImageInfo function in image
osv·2006-01-04·CVSS 7.5
CVE-2006-0082 [HIGH] CVE-2006-0082: Format string vulnerability in the SetImageInfo function in image
Format string vulnerability in the SetImageInfo function in image.c for ImageMagick 6.2.3 and other versions, and GraphicsMagick, allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a numeric format string specifier such as %d in the file name, a variant of CVE-2005-0397, and as demonstrated using the convert program.
OSV
CVE-2005-0397: Format string vulnerability in the SetImageInfo function in image
osv·2005-05-02·CVSS 7.5
CVE-2005-0397 [HIGH] CVE-2005-0397: Format string vulnerability in the SetImageInfo function in image
Format string vulnerability in the SetImageInfo function in image.c for ImageMagick before 6.0.2.5 may allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a filename argument to convert, which may be called by other web applications.
Red Hat
security flaw
vendor_redhat·2006-01-04·CVSS 7.5
CVE-2006-0082 [HIGH] security flaw
security flaw
Format string vulnerability in the SetImageInfo function in image.c for ImageMagick 6.2.3 and other versions, and GraphicsMagick, allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a numeric format string specifier such as %d in the file name, a variant of CVE-2005-0397, and as demonstrated using the convert program.
Debian
CVE-2006-0082: imagemagick - Format string vulnerability in the SetImageInfo function in image.c for ImageMag...
vendor_debian·2006·CVSS 7.5
CVE-2006-0082 [HIGH] CVE-2006-0082: imagemagick - Format string vulnerability in the SetImageInfo function in image.c for ImageMag...
Format string vulnerability in the SetImageInfo function in image.c for ImageMagick 6.2.3 and other versions, and GraphicsMagick, allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a numeric format string specifier such as %d in the file name, a variant of CVE-2005-0397, and as demonstrated using the convert program.
Scope: local
bookworm: resolved (fixed in 6:6.2.4.5-0.6)
bullseye: resolved (fixed in 6:6.2.4.5-0.6)
forky: resolved (fixed in 6:6.2.4.5-0.6)
sid: resolved (fixed in 6:6.2.4.5-0.6)
trixie: resolved (fixed in 6:6.2.4.5-0.6)
Ubuntu
Imagemagick vulnerability
vendor_ubuntu·2005-03-03
CVE-2005-0397 Imagemagick vulnerability
Title: Imagemagick vulnerability
Summary: Imagemagick vulnerability
Tavis Ormandy discovered a format string vulnerability in ImageMagick's file
name handling. Specially crafted file names could cause a program using
ImageMagick to crash, or possibly even cause execution of arbitrary code.
Since ImageMagick can be used in custom printing systems, this also might lead
to privilege escalation (execute code with the printer spooler's privileges).
However, Ubuntu's standard printing system does not use ImageMagick, thus there
is no risk of privilege escalation in a standard installation.
ImageMagick is also commonly used by web frontends; if these accept image
uploads with arbitrary file names, this could also lead to remote privilege
escalation.
Instructions: In general, a standard syste
Red Hat
security flaw
vendor_redhat·2005-02-02·CVSS 7.5
CVE-2005-0397 [HIGH] security flaw
security flaw
Format string vulnerability in the SetImageInfo function in image.c for ImageMagick before 6.0.2.5 may allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a filename argument to convert, which may be called by other web applications.
Debian
CVE-2005-0397: graphicsmagick - Format string vulnerability in the SetImageInfo function in image.c for ImageMag...
vendor_debian·2005·CVSS 7.5
CVE-2005-0397 [HIGH] CVE-2005-0397: graphicsmagick - Format string vulnerability in the SetImageInfo function in image.c for ImageMag...
Format string vulnerability in the SetImageInfo function in image.c for ImageMagick before 6.0.2.5 may allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a filename argument to convert, which may be called by other web applications.
Scope: local
bookworm: resolved (fixed in 1.1.7-1)
bullseye: resolved (fixed in 1.1.7-1)
forky: resolved (fixed in 1.1.7-1)
sid: resolved (fixed in 1.1.7-1)
trixie: resolved (fixed in 1.1.7-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-0397 security flaw
bugzilla·2018-08-16·CVSS 7.5
CVE-2005-0397 [HIGH] CVE-2005-0397 security flaw
CVE-2005-0397 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Format string vulnerability in the SetImageInfo function in image.c for ImageMagick before 6.0.2.5 may allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a filename argument to convert, which may be called by other web applications.
Bugzilla
CVE-2006-0082 security flaw
bugzilla·2018-08-16·CVSS 7.5
CVE-2006-0082 [HIGH] CVE-2006-0082 security flaw
CVE-2006-0082 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Format string vulnerability in the SetImageInfo function in image.c for ImageMagick 6.2.3 and other versions, and GraphicsMagick, allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a numeric format string specifier such as %d in the file name, a variant of CVE-2005-0397, and as demonstrated using the convert program.
Bugzilla
CVE-2006-0082 ImageMagick format string vulnerability.
bugzilla·2006-01-04·CVSS 7.5
CVE-2006-0082 [HIGH] CVE-2006-0082 ImageMagick format string vulnerability.
CVE-2006-0082 ImageMagick format string vulnerability.
ImageMagick format string vulnerability.
The fix for CVE-2005-0397 is incomplete. As the Debian bug suggests,
by running a command such as:
convert file.jpg file%d%n.jpg
A segfault will result in ImageMagick.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345876
This issue also affects RHEL3
This issue also affects RHEL2.1
Discussion:
The fix in the debian bug is incomplete, the same code is repeated in blob.c
---
Created attachment 122767
patch for 6.2.5 (Rawhide)
---
Created attachment 122771
patch for 6.0.7 (RHEL 4)
---
Created attachment 122772
patch for 5.5.6 (RHEL 3)
---
Created attachment 122773
patch for 5.3.8 (RHEL 2.1)
---
The fixes are contained in
ImageMagick-6.0.7.1-14 (RHEL4)
ImageMagick-5.5.6-17 (RHE
Bugzilla
CVE-2006-0082 ImageMagick format string vulnerability. Also CVE-2005-4601, CVE-2006-2440, CVE-2006-3743, CVE-2006-3744, CVE-2006-4144.
bugzilla·2006-01-04·CVSS 7.5
CVE-2006-0082 [HIGH] CVE-2006-0082 ImageMagick format string vulnerability. Also CVE-2005-4601, CVE-2006-2440, CVE-2006-3743, CVE-2006-3744, CVE-2006-4144.
CVE-2006-0082 ImageMagick format string vulnerability. Also CVE-2005-4601, CVE-2006-2440, CVE-2006-3743, CVE-2006-3744, CVE-2006-4144.
ImageMagick format string vulnerability.
The fix for CVE-2005-0397 is incomplete. As the Debian bug suggests,
by running a command such as:
convert file.jpg file%d%n.jpg
A segfault will result in ImageMagick.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345876
Discussion:
From User-Agent: XML-RPC
ImageMagick-6.2.2.0-3.fc4.1 has been pushed for FC4, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report.
---
I see updates have been released for FC4 - any chance to get the fixes applied
to FC3 as well? I know it has been transfered to legacy - however
security-support
http://bugs.gentoo.org/show_bug.cgi?id=83542http://marc.info/?l=bugtraq&m=110987256010857&w=2http://www.debian.org/security/2005/dsa-702http://www.gentoo.org/security/en/glsa/glsa-200503-11.xmlhttp://www.novell.com/linux/security/advisories/2005_17_imagemagick.htmlhttp://www.redhat.com/support/errata/RHSA-2005-070.htmlhttp://www.redhat.com/support/errata/RHSA-2005-320.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/19586https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10302http://bugs.gentoo.org/show_bug.cgi?id=83542http://marc.info/?l=bugtraq&m=110987256010857&w=2http://www.debian.org/security/2005/dsa-702http://www.gentoo.org/security/en/glsa/glsa-200503-11.xmlhttp://www.novell.com/linux/security/advisories/2005_17_imagemagick.htmlhttp://www.redhat.com/support/errata/RHSA-2005-070.htmlhttp://www.redhat.com/support/errata/RHSA-2005-320.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/19586https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10302
2005-05-02
Published