CVE-2006-0082
published 2006-01-04CVE-2006-0082: Format string vulnerability in the SetImageInfo function in image.c for ImageMagick 6.2.3 and other versions, and GraphicsMagick, allows user-assisted…
PriorityP422medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
4.34%
90.1th percentile
Format string vulnerability in the SetImageInfo function in image.c for ImageMagick 6.2.3 and other versions, and GraphicsMagick, allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a numeric format string specifier such as %d in the file name, a variant of CVE-2005-0397, and as demonstrated using the convert program.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imagemagick | < imagemagick 6:6.2.4.5-0.6 (bookworm) | imagemagick 6:6.2.4.5-0.6 (bookworm) |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | >= 0 < 6:6.2.4.5-0.6 | 6:6.2.4.5-0.6 |
| imagemagick | imagemagick | >= 0 < 6:6.2.4.5-0.6 | 6:6.2.4.5-0.6 |
| imagemagick | imagemagick | >= 0 < 6:6.2.4.5-0.6 | 6:6.2.4.5-0.6 |
| imagemagick | imagemagick | >= 0 < 6:6.2.4.5-0.6 | 6:6.2.4.5-0.6 |
CVSS provenance
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gqwr-p67x-5fff: Format string vulnerability in the SetImageInfo function in image
ghsa_unreviewed·2022-05-03·CVSS 7.5
CVE-2006-0082 [HIGH] CWE-134 GHSA-gqwr-p67x-5fff: Format string vulnerability in the SetImageInfo function in image
Format string vulnerability in the SetImageInfo function in image.c for ImageMagick 6.2.3 and other versions, and GraphicsMagick, allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a numeric format string specifier such as %d in the file name, a variant of CVE-2005-0397, and as demonstrated using the convert program.
OSV
CVE-2006-0082: Format string vulnerability in the SetImageInfo function in image
osv·2006-01-04·CVSS 7.5
CVE-2006-0082 [HIGH] CVE-2006-0082: Format string vulnerability in the SetImageInfo function in image
Format string vulnerability in the SetImageInfo function in image.c for ImageMagick 6.2.3 and other versions, and GraphicsMagick, allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a numeric format string specifier such as %d in the file name, a variant of CVE-2005-0397, and as demonstrated using the convert program.
Ubuntu
imagemagick vulnerabilities
vendor_ubuntu·2006-01-25·CVSS 7.5
CVE-2005-4601 [HIGH] imagemagick vulnerabilities
Title: imagemagick vulnerabilities
Summary: imagemagick vulnerabilities
Florian Weimer discovered that the delegate code did not correctly
handle file names which embed shell commands (CVE-2005-4601). Daniel
Kobras found a format string vulnerability in the SetImageInfo()
function (CVE-2006-0082). By tricking a user into processing an image
file with a specially crafted file name, these two vulnerabilities
could be exploited to execute arbitrary commands with the user's
privileges. These vulnerability become particularly critical if
malicious images are sent as email attachments and the email client
uses imagemagick to convert/display the images (e. g. Thunderbird and
Gnus).
In addition, Eero Häkkinen reported a bug in the command line argument
processing of the 'display' command. Argum
Red Hat
security flaw
vendor_redhat·2006-01-04·CVSS 7.5
CVE-2006-0082 [HIGH] security flaw
security flaw
Format string vulnerability in the SetImageInfo function in image.c for ImageMagick 6.2.3 and other versions, and GraphicsMagick, allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a numeric format string specifier such as %d in the file name, a variant of CVE-2005-0397, and as demonstrated using the convert program.
Debian
CVE-2006-0082: imagemagick - Format string vulnerability in the SetImageInfo function in image.c for ImageMag...
vendor_debian·2006·CVSS 7.5
CVE-2006-0082 [HIGH] CVE-2006-0082: imagemagick - Format string vulnerability in the SetImageInfo function in image.c for ImageMag...
Format string vulnerability in the SetImageInfo function in image.c for ImageMagick 6.2.3 and other versions, and GraphicsMagick, allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a numeric format string specifier such as %d in the file name, a variant of CVE-2005-0397, and as demonstrated using the convert program.
Scope: local
bookworm: resolved (fixed in 6:6.2.4.5-0.6)
bullseye: resolved (fixed in 6:6.2.4.5-0.6)
forky: resolved (fixed in 6:6.2.4.5-0.6)
sid: resolved (fixed in 6:6.2.4.5-0.6)
trixie: resolved (fixed in 6:6.2.4.5-0.6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-0082 security flaw
bugzilla·2018-08-16·CVSS 7.5
CVE-2006-0082 [HIGH] CVE-2006-0082 security flaw
CVE-2006-0082 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Format string vulnerability in the SetImageInfo function in image.c for ImageMagick 6.2.3 and other versions, and GraphicsMagick, allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a numeric format string specifier such as %d in the file name, a variant of CVE-2005-0397, and as demonstrated using the convert program.
Bugzilla
CVE-2006-0082 ImageMagick format string vulnerability.
bugzilla·2006-01-04·CVSS 7.5
CVE-2006-0082 [HIGH] CVE-2006-0082 ImageMagick format string vulnerability.
CVE-2006-0082 ImageMagick format string vulnerability.
ImageMagick format string vulnerability.
The fix for CVE-2005-0397 is incomplete. As the Debian bug suggests,
by running a command such as:
convert file.jpg file%d%n.jpg
A segfault will result in ImageMagick.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345876
This issue also affects RHEL3
This issue also affects RHEL2.1
Discussion:
The fix in the debian bug is incomplete, the same code is repeated in blob.c
---
Created attachment 122767
patch for 6.2.5 (Rawhide)
---
Created attachment 122771
patch for 6.0.7 (RHEL 4)
---
Created attachment 122772
patch for 5.5.6 (RHEL 3)
---
Created attachment 122773
patch for 5.3.8 (RHEL 2.1)
---
The fixes are contained in
ImageMagick-6.0.7.1-14 (RHEL4)
ImageMagick-5.5.6-17 (RHE
Bugzilla
CVE-2006-0082 ImageMagick format string vulnerability. Also CVE-2005-4601, CVE-2006-2440, CVE-2006-3743, CVE-2006-3744, CVE-2006-4144.
bugzilla·2006-01-04·CVSS 7.5
CVE-2006-0082 [HIGH] CVE-2006-0082 ImageMagick format string vulnerability. Also CVE-2005-4601, CVE-2006-2440, CVE-2006-3743, CVE-2006-3744, CVE-2006-4144.
CVE-2006-0082 ImageMagick format string vulnerability. Also CVE-2005-4601, CVE-2006-2440, CVE-2006-3743, CVE-2006-3744, CVE-2006-4144.
ImageMagick format string vulnerability.
The fix for CVE-2005-0397 is incomplete. As the Debian bug suggests,
by running a command such as:
convert file.jpg file%d%n.jpg
A segfault will result in ImageMagick.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345876
Discussion:
From User-Agent: XML-RPC
ImageMagick-6.2.2.0-3.fc4.1 has been pushed for FC4, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report.
---
I see updates have been released for FC4 - any chance to get the fixes applied
to FC3 as well? I know it has been transfered to legacy - however
security-support
ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.aschttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345876http://rhn.redhat.com/errata/RHSA-2006-0178.htmlhttp://secunia.com/advisories/18261http://secunia.com/advisories/18607http://secunia.com/advisories/18851http://secunia.com/advisories/18871http://secunia.com/advisories/19030http://secunia.com/advisories/19183http://secunia.com/advisories/19408http://secunia.com/advisories/22998http://secunia.com/advisories/23090http://secunia.com/advisories/28800http://securityreason.com/securityalert/500http://securitytracker.com/id?1015623http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.341682http://sunsolve.sun.com/search/document.do?assetkey=1-26-231321-1http://www.debian.org/security/2006/dsa-1213http://www.gentoo.org/security/en/glsa/glsa-200602-06.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200602-13.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:024http://www.novell.com/linux/security/advisories/2006_06_sr.htmlhttp://www.securityfocus.com/archive/1/452718/100/100/threadedhttp://www.securityfocus.com/bid/12717http://www.ubuntu.com/usn/usn-246-1http://www.vupen.com/english/advisories/2008/0412https://issues.rpath.com/browse/RPL-389https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10717ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.aschttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345876http://rhn.redhat.com/errata/RHSA-2006-0178.htmlhttp://secunia.com/advisories/18261http://secunia.com/advisories/18607http://secunia.com/advisories/18851http://secunia.com/advisories/18871http://secunia.com/advisories/19030http://secunia.com/advisories/19183http://secunia.com/advisories/19408http://secunia.com/advisories/22998http://secunia.com/advisories/23090http://secunia.com/advisories/28800http://securityreason.com/securityalert/500http://securitytracker.com/id?1015623http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.341682http://sunsolve.sun.com/search/document.do?assetkey=1-26-231321-1http://www.debian.org/security/2006/dsa-1213http://www.gentoo.org/security/en/glsa/glsa-200602-06.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200602-13.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:024http://www.novell.com/linux/security/advisories/2006_06_sr.htmlhttp://www.securityfocus.com/archive/1/452718/100/100/threadedhttp://www.securityfocus.com/bid/12717http://www.ubuntu.com/usn/usn-246-1http://www.vupen.com/english/advisories/2008/0412https://issues.rpath.com/browse/RPL-389https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10717
2006-01-04
Published