CVE-2005-4601Imagemagick vulnerability

9 documents7 sources
Severity
7.5HIGHNVD
EPSS
11.9%
top 6.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 31
Latest updateMay 3

Description

The delegate code in ImageMagick 6.2.4.5-0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename that is processed by the display command.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages5 packages

debiandebian/imagemagick< graphicsmagick 1.1.7-1 (bookworm)
Debianimagemagick/imagemagick< 6:6.2.4.5-0.6+3
debiandebian/graphicsmagick< graphicsmagick 1.1.7-1 (bookworm)
Debiangraphicsmagick/graphicsmagick< 1.1.7-1+3

🔴Vulnerability Details

2
GHSA
GHSA-5jj5-jc9x-8v3m: The delegate code in ImageMagick 62022-05-03
OSV
CVE-2005-4601: The delegate code in ImageMagick 62005-12-31

📋Vendor Advisories

3
Ubuntu
imagemagick vulnerabilities2006-01-25
Red Hat
security flaw2005-12-29
Debian
CVE-2005-4601: graphicsmagick - The delegate code in ImageMagick 6.2.4.5-0.3 allows remote attackers to execute ...2005

💬Community

3
Bugzilla
CVE-2005-4601 security flaw2018-08-16
Bugzilla
CVE-2006-0082 ImageMagick format string vulnerability. Also CVE-2005-4601, CVE-2006-2440, CVE-2006-3743, CVE-2006-3744, CVE-2006-4144.2006-01-04
Bugzilla
CVE-2005-4601 ImageMagick display command shell command injection2006-01-03