CVE-2005-0397 — Use of Externally-Controlled Format String in Imagemagick
Severity
7.5HIGHNVD
NVD5.1
EPSS
4.5%
top 10.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 2
Latest updateMay 3
Description
Format string vulnerability in the SetImageInfo function in image.c for ImageMagick before 6.0.2.5 may allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a filename argument to convert, which may be called by other web applications.
CVSS vector
AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4
Affected Packages5 packages
Patches
🔴Vulnerability Details
4GHSA
▶
GHSA
▶
📋Vendor Advisories
5💬Community
4Bugzilla▶
CVE-2006-0082 ImageMagick format string vulnerability. Also CVE-2005-4601, CVE-2006-2440, CVE-2006-3743, CVE-2006-3744, CVE-2006-4144.↗2006-01-04