CVE-2005-0397Use of Externally-Controlled Format String in Imagemagick

Severity
7.5HIGHNVD
NVD5.1
EPSS
4.5%
top 10.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 2
Latest updateMay 3

Description

Format string vulnerability in the SetImageInfo function in image.c for ImageMagick before 6.0.2.5 may allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a filename argument to convert, which may be called by other web applications.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages5 packages

debiandebian/imagemagick< graphicsmagick 1.1.7-1 (bookworm)+1
Debianimagemagick/imagemagick< 6:6.0.6.2-2.2+7
NVDimagemagick/imagemagick5 versions+4
debiandebian/graphicsmagick< graphicsmagick 1.1.7-1 (bookworm)
Debiangraphicsmagick/graphicsmagick< 1.1.7-1+3

Patches

🔴Vulnerability Details

4
GHSA
GHSA-gqwr-p67x-5fff: Format string vulnerability in the SetImageInfo function in image2022-05-03
GHSA
GHSA-9qw2-jqcg-348f: Format string vulnerability in the SetImageInfo function in image2022-05-01
OSV
CVE-2006-0082: Format string vulnerability in the SetImageInfo function in image2006-01-04
OSV
CVE-2005-0397: Format string vulnerability in the SetImageInfo function in image2005-05-02

📋Vendor Advisories

5
Red Hat
security flaw2006-01-04
Debian
CVE-2006-0082: imagemagick - Format string vulnerability in the SetImageInfo function in image.c for ImageMag...2006
Ubuntu
Imagemagick vulnerability2005-03-03
Red Hat
security flaw2005-02-02
Debian
CVE-2005-0397: graphicsmagick - Format string vulnerability in the SetImageInfo function in image.c for ImageMag...2005

💬Community

4
Bugzilla
CVE-2005-0397 security flaw2018-08-16
Bugzilla
CVE-2006-0082 security flaw2018-08-16
Bugzilla
CVE-2006-0082 ImageMagick format string vulnerability.2006-01-04
Bugzilla
CVE-2006-0082 ImageMagick format string vulnerability. Also CVE-2005-4601, CVE-2006-2440, CVE-2006-3743, CVE-2006-3744, CVE-2006-4144.2006-01-04