CVE-2005-0762Improper Restriction of Operations within the Bounds of a Memory Buffer in Imagemagick

6 documents6 sources
Severity
7.5HIGHNVD
EPSS
3.1%
top 13.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 2
Latest updateMay 1

Description

Heap-based buffer overflow in the SGI parser in ImageMagick before 6.0 allows remote attackers to execute arbitrary code via a crafted SGI image file.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

debiandebian/imagemagick< imagemagick 5:6.0.0-1 (bookworm)
Debianimagemagick/imagemagick< 5:6.0.0-1+3
NVDimagemagick/imagemagick14 versions+13

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5vp3-qfr9-9m96: Heap-based buffer overflow in the SGI parser in ImageMagick before 62022-05-01
OSV
CVE-2005-0762: Heap-based buffer overflow in the SGI parser in ImageMagick before 62005-05-02

📋Vendor Advisories

2
Debian
CVE-2005-0762: imagemagick - Heap-based buffer overflow in the SGI parser in ImageMagick before 6.0 allows re...2005
Red Hat
security flaw2004-06-09

💬Community

1
Bugzilla
CVE-2005-0762 security flaw2018-08-16