CVE-2005-4601
published 2005-12-31CVE-2005-4601: The delegate code in ImageMagick 6.2.4.5-0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename that is processed by…
PriorityP342high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.69%
88.5th percentile
The delegate code in ImageMagick 6.2.4.5-0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename that is processed by the display command.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | graphicsmagick | < graphicsmagick 1.1.7-1 (bookworm) | graphicsmagick 1.1.7-1 (bookworm) |
| debian | imagemagick | < graphicsmagick 1.1.7-1 (bookworm) | graphicsmagick 1.1.7-1 (bookworm) |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.7-1 | 1.1.7-1 |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.7-1 | 1.1.7-1 |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.7-1 | 1.1.7-1 |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.7-1 | 1.1.7-1 |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | >= 0 < 6:6.2.4.5-0.6 | 6:6.2.4.5-0.6 |
| imagemagick | imagemagick | >= 0 < 6:6.2.4.5-0.6 | 6:6.2.4.5-0.6 |
| imagemagick | imagemagick | >= 0 < 6:6.2.4.5-0.6 | 6:6.2.4.5-0.6 |
| imagemagick | imagemagick | >= 0 < 6:6.2.4.5-0.6 | 6:6.2.4.5-0.6 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
imagemagick vulnerabilities
vendor_ubuntu·2006-01-25·CVSS 7.5
CVE-2005-4601 [HIGH] imagemagick vulnerabilities
Title: imagemagick vulnerabilities
Summary: imagemagick vulnerabilities
Florian Weimer discovered that the delegate code did not correctly
handle file names which embed shell commands (CVE-2005-4601). Daniel
Kobras found a format string vulnerability in the SetImageInfo()
function (CVE-2006-0082). By tricking a user into processing an image
file with a specially crafted file name, these two vulnerabilities
could be exploited to execute arbitrary commands with the user's
privileges. These vulnerability become particularly critical if
malicious images are sent as email attachments and the email client
uses imagemagick to convert/display the images (e. g. Thunderbird and
Gnus).
In addition, Eero Häkkinen reported a bug in the command line argument
processing of the 'display' command. Argum
Red Hat
security flaw
vendor_redhat·2005-12-29·CVSS 7.5
CVE-2005-4601 [HIGH] security flaw
security flaw
The delegate code in ImageMagick 6.2.4.5-0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename that is processed by the display command.
Debian
CVE-2005-4601: graphicsmagick - The delegate code in ImageMagick 6.2.4.5-0.3 allows remote attackers to execute ...
vendor_debian·2005·CVSS 7.5
CVE-2005-4601 [HIGH] CVE-2005-4601: graphicsmagick - The delegate code in ImageMagick 6.2.4.5-0.3 allows remote attackers to execute ...
The delegate code in ImageMagick 6.2.4.5-0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename that is processed by the display command.
Scope: local
bookworm: resolved (fixed in 1.1.7-1)
bullseye: resolved (fixed in 1.1.7-1)
forky: resolved (fixed in 1.1.7-1)
sid: resolved (fixed in 1.1.7-1)
trixie: resolved (fixed in 1.1.7-1)
GHSA
GHSA-5jj5-jc9x-8v3m: The delegate code in ImageMagick 6
ghsa_unreviewed·2022-05-03
CVE-2005-4601 [HIGH] GHSA-5jj5-jc9x-8v3m: The delegate code in ImageMagick 6
The delegate code in ImageMagick 6.2.4.5-0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename that is processed by the display command.
OSV
CVE-2005-4601: The delegate code in ImageMagick 6
osv·2005-12-31·CVSS 7.5
CVE-2005-4601 [HIGH] CVE-2005-4601: The delegate code in ImageMagick 6
The delegate code in ImageMagick 6.2.4.5-0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename that is processed by the display command.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-4601 security flaw
bugzilla·2018-08-16·CVSS 7.5
CVE-2005-4601 [HIGH] CVE-2005-4601 security flaw
CVE-2005-4601 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
The delegate code in ImageMagick 6.2.4.5-0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename that is processed by the display command.
Bugzilla
CVE-2006-0082 ImageMagick format string vulnerability. Also CVE-2005-4601, CVE-2006-2440, CVE-2006-3743, CVE-2006-3744, CVE-2006-4144.
bugzilla·2006-01-04·CVSS 7.5
CVE-2006-0082 [HIGH] CVE-2006-0082 ImageMagick format string vulnerability. Also CVE-2005-4601, CVE-2006-2440, CVE-2006-3743, CVE-2006-3744, CVE-2006-4144.
CVE-2006-0082 ImageMagick format string vulnerability. Also CVE-2005-4601, CVE-2006-2440, CVE-2006-3743, CVE-2006-3744, CVE-2006-4144.
ImageMagick format string vulnerability.
The fix for CVE-2005-0397 is incomplete. As the Debian bug suggests,
by running a command such as:
convert file.jpg file%d%n.jpg
A segfault will result in ImageMagick.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345876
Discussion:
From User-Agent: XML-RPC
ImageMagick-6.2.2.0-3.fc4.1 has been pushed for FC4, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report.
---
I see updates have been released for FC4 - any chance to get the fixes applied
to FC3 as well? I know it has been transfered to legacy - however
security-support
Bugzilla
CVE-2005-4601 ImageMagick display command shell command injection
bugzilla·2006-01-03·CVSS 7.5
CVE-2005-4601 [HIGH] CVE-2005-4601 ImageMagick display command shell command injection
CVE-2005-4601 ImageMagick display command shell command injection
ImageMagick display command shell command injection
When displaying an image in ImageMagick with a carefully crafted
filename, it is possible to execute arbitrary commands.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345238
This issue also affects RHEL3
This issue also affects RHEL2.1
Discussion:
Created attachment 122886
patch for 6.0.7 (RHEL 4)
---
Created attachment 122887
patch for 5.5.6 (RHEL 3)
---
Created attachment 122888
patch for 5.3.8 (RHEL 2.1)
---
The fixes are contained in
ImageMagick-6.0.7.1-14 (RHEL4)
ImageMagick-5.5.6-17 (RHEL 3)
ImageMagick-5.3.8-14 (RHEL 2.1)
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed
ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.aschttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345238http://rhn.redhat.com/errata/RHSA-2006-0178.htmlhttp://secunia.com/advisories/18261http://secunia.com/advisories/18607http://secunia.com/advisories/18631http://secunia.com/advisories/18871http://secunia.com/advisories/19183http://secunia.com/advisories/19408http://secunia.com/advisories/23090http://secunia.com/advisories/28800http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.341682http://sunsolve.sun.com/search/document.do?assetkey=1-26-231321-1http://www.debian.org/security/2006/dsa-957http://www.mandriva.com/security/advisories?name=MDKSA-2006:024http://www.novell.com/linux/security/advisories/2006_06_sr.htmlhttp://www.osvdb.org/22121http://www.securityfocus.com/archive/1/452718/100/100/threadedhttp://www.securityfocus.com/bid/16093http://www.ubuntu.com/usn/usn-246-1http://www.vupen.com/english/advisories/2008/0412https://exchange.xforce.ibmcloud.com/vulnerabilities/23927https://issues.rpath.com/browse/RPL-389https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10353ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.aschttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345238http://rhn.redhat.com/errata/RHSA-2006-0178.htmlhttp://secunia.com/advisories/18261http://secunia.com/advisories/18607http://secunia.com/advisories/18631http://secunia.com/advisories/18871http://secunia.com/advisories/19183http://secunia.com/advisories/19408http://secunia.com/advisories/23090http://secunia.com/advisories/28800http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.341682http://sunsolve.sun.com/search/document.do?assetkey=1-26-231321-1http://www.debian.org/security/2006/dsa-957http://www.mandriva.com/security/advisories?name=MDKSA-2006:024http://www.novell.com/linux/security/advisories/2006_06_sr.htmlhttp://www.osvdb.org/22121http://www.securityfocus.com/archive/1/452718/100/100/threadedhttp://www.securityfocus.com/bid/16093http://www.ubuntu.com/usn/usn-246-1http://www.vupen.com/english/advisories/2008/0412https://exchange.xforce.ibmcloud.com/vulnerabilities/23927https://issues.rpath.com/browse/RPL-389https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10353
2005-12-31
Published