CVE-2006-2440
published 2006-05-18CVE-2006-2440: Heap-based buffer overflow in the libMagick component of ImageMagick 6.0.6.2 might allow attackers to execute arbitrary code via an image index array that…
PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.86%
85.3th percentile
Heap-based buffer overflow in the libMagick component of ImageMagick 6.0.6.2 might allow attackers to execute arbitrary code via an image index array that triggers the overflow during filename glob expansion by the ExpandFilenames function.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imagemagick | < imagemagick 6:6.2.4.5-0.6 (bookworm) | imagemagick 6:6.2.4.5-0.6 (bookworm) |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | >= 0 < 6:6.2.4.5-0.6 | 6:6.2.4.5-0.6 |
| imagemagick | imagemagick | >= 0 < 6:6.2.4.5-0.6 | 6:6.2.4.5-0.6 |
| imagemagick | imagemagick | >= 0 < 6:6.2.4.5-0.6 | 6:6.2.4.5-0.6 |
| imagemagick | imagemagick | >= 0 < 6:6.2.4.5-0.6 | 6:6.2.4.5-0.6 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g4fx-7rrq-8736: Heap-based buffer overflow in the libMagick component of ImageMagick 6
ghsa_unreviewed·2022-05-03
CVE-2006-2440 [HIGH] GHSA-g4fx-7rrq-8736: Heap-based buffer overflow in the libMagick component of ImageMagick 6
Heap-based buffer overflow in the libMagick component of ImageMagick 6.0.6.2 might allow attackers to execute arbitrary code via an image index array that triggers the overflow during filename glob expansion by the ExpandFilenames function.
OSV
CVE-2006-2440: Heap-based buffer overflow in the libMagick component of ImageMagick 6
osv·2006-05-18·CVSS 7.5
CVE-2006-2440 [HIGH] CVE-2006-2440: Heap-based buffer overflow in the libMagick component of ImageMagick 6
Heap-based buffer overflow in the libMagick component of ImageMagick 6.0.6.2 might allow attackers to execute arbitrary code via an image index array that triggers the overflow during filename glob expansion by the ExpandFilenames function.
Red Hat
security flaw
vendor_redhat·2006-01-02·CVSS 7.5
CVE-2006-2440 [HIGH] security flaw
security flaw
Heap-based buffer overflow in the libMagick component of ImageMagick 6.0.6.2 might allow attackers to execute arbitrary code via an image index array that triggers the overflow during filename glob expansion by the ExpandFilenames function.
Statement: Red Hat is aware of this issue and is tracking it via the following bug:
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=192278
The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw. More information regarding issue severity can be found here:
http://www.redhat.com/security/updates/classification/
This issue does not affect Red Hat Enterprise Linux 2.1 or 3.
Debian
CVE-2006-2440: imagemagick - Heap-based buffer overflow in the libMagick component of ImageMagick 6.0.6.2 mig...
vendor_debian·2006·CVSS 7.5
CVE-2006-2440 [HIGH] CVE-2006-2440: imagemagick - Heap-based buffer overflow in the libMagick component of ImageMagick 6.0.6.2 mig...
Heap-based buffer overflow in the libMagick component of ImageMagick 6.0.6.2 might allow attackers to execute arbitrary code via an image index array that triggers the overflow during filename glob expansion by the ExpandFilenames function.
Scope: local
bookworm: resolved (fixed in 6:6.2.4.5-0.6)
bullseye: resolved (fixed in 6:6.2.4.5-0.6)
forky: resolved (fixed in 6:6.2.4.5-0.6)
sid: resolved (fixed in 6:6.2.4.5-0.6)
trixie: resolved (fixed in 6:6.2.4.5-0.6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-2440 security flaw
bugzilla·2018-08-16·CVSS 7.5
CVE-2006-2440 [HIGH] CVE-2006-2440 security flaw
CVE-2006-2440 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Heap-based buffer overflow in the libMagick component of ImageMagick 6.0.6.2 might allow attackers to execute arbitrary code via an image index array that triggers the overflow during filename glob expansion by the ExpandFilenames function.
---
Statement:
Red Hat is aware of this issue and is tracking it via the following bug:
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=192278
The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw. More information regarding issue severity can be found here:
http://www.redhat.com/securit
Bugzilla
CVE-2006-2440 ImageMagick heap overflow
bugzilla·2006-05-18·CVSS 7.5
CVE-2006-2440 [HIGH] CVE-2006-2440 ImageMagick heap overflow
CVE-2006-2440 ImageMagick heap overflow
ImageMagick heap overflow
ImageMagick's DisplayImageCommand contains a heap overflow flaw. It
is possible to pass an unexpanded glob to ImageMagick which will be
expanded by ImageMagick and overflow heap memory.
The patch and more information can be found in the Debian bug:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345595
This issue also affects FC4
Discussion:
ImageMagick-6.2.5.4-4.2.1.fc5.2 has been pushed for fc5, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report.
---
This bug also seems to track the fc4 version of ImageMagick.
As noted above, ImageMagick-6.2.5.4-4.2.1.fc5.2 was pushed to updates for fc5.
.
Also, ImageMagick-6.2.2.0-3.fc4.2 was pus
Bugzilla
CVE-2006-2440 ImageMagick heap overflow
bugzilla·2006-05-18·CVSS 7.5
CVE-2006-2440 [HIGH] CVE-2006-2440 ImageMagick heap overflow
CVE-2006-2440 ImageMagick heap overflow
ImageMagick heap overflow
ImageMagick's DisplayImageCommand contains a heap overflow flaw. It
is possible to pass an unexpanded glob to ImageMagick which will be
expanded by ImageMagick and overflow heap memory.
The patch and more information can be found in the Debian bug:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345595
Discussion:
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2007-0015.html
Bugzilla
CVE-2006-0082 ImageMagick format string vulnerability. Also CVE-2005-4601, CVE-2006-2440, CVE-2006-3743, CVE-2006-3744, CVE-2006-4144.
bugzilla·2006-01-04·CVSS 7.5
CVE-2006-0082 [HIGH] CVE-2006-0082 ImageMagick format string vulnerability. Also CVE-2005-4601, CVE-2006-2440, CVE-2006-3743, CVE-2006-3744, CVE-2006-4144.
CVE-2006-0082 ImageMagick format string vulnerability. Also CVE-2005-4601, CVE-2006-2440, CVE-2006-3743, CVE-2006-3744, CVE-2006-4144.
ImageMagick format string vulnerability.
The fix for CVE-2005-0397 is incomplete. As the Debian bug suggests,
by running a command such as:
convert file.jpg file%d%n.jpg
A segfault will result in ImageMagick.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345876
Discussion:
From User-Agent: XML-RPC
ImageMagick-6.2.2.0-3.fc4.1 has been pushed for FC4, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report.
---
I see updates have been released for FC4 - any chance to get the fixes applied
to FC3 as well? I know it has been transfered to legacy - however
security-support
ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.aschttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345595http://secunia.com/advisories/21719http://secunia.com/advisories/24186http://secunia.com/advisories/24284http://www.debian.org/security/2006/dsa-1168http://www.redhat.com/support/errata/RHSA-2007-0015.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9481ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.aschttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345595http://secunia.com/advisories/21719http://secunia.com/advisories/24186http://secunia.com/advisories/24284http://www.debian.org/security/2006/dsa-1168http://www.redhat.com/support/errata/RHSA-2007-0015.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9481
2006-05-18
Published