CVE-2006-3743
published 2006-08-25CVE-2006-3743: Multiple buffer overflows in ImageMagick before 6.2.9 allow user-assisted attackers to execute arbitrary code via crafted XCF images.
PriorityP427medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
3.61%
88.3th percentile
Multiple buffer overflows in ImageMagick before 6.2.9 allow user-assisted attackers to execute arbitrary code via crafted XCF images.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | graphicsmagick | < graphicsmagick 1.1.7-8 (bookworm) | graphicsmagick 1.1.7-8 (bookworm) |
| debian | imagemagick | < graphicsmagick 1.1.7-8 (bookworm) | graphicsmagick 1.1.7-8 (bookworm) |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.7-8 | 1.1.7-8 |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.7-8 | 1.1.7-8 |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.7-8 | 1.1.7-8 |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.7-8 | 1.1.7-8 |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | >= 0 < 7:6.2.4.5.dfsg1-0.10 | 7:6.2.4.5.dfsg1-0.10 |
| imagemagick | imagemagick | >= 0 < 7:6.2.4.5.dfsg1-0.10 | 7:6.2.4.5.dfsg1-0.10 |
| imagemagick | imagemagick | >= 0 < 7:6.2.4.5.dfsg1-0.10 | 7:6.2.4.5.dfsg1-0.10 |
CVSS provenance
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv5.1MEDIUM
vendor_debian5.1MEDIUM
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vwf7-7g8c-h7pw: Multiple buffer overflows in ImageMagick before 6
ghsa_unreviewed·2022-05-03
CVE-2006-3743 [MEDIUM] GHSA-vwf7-7g8c-h7pw: Multiple buffer overflows in ImageMagick before 6
Multiple buffer overflows in ImageMagick before 6.2.9 allow user-assisted attackers to execute arbitrary code via crafted XCF images.
OSV
CVE-2006-3743: Multiple buffer overflows in ImageMagick before 6
osv·2006-08-25·CVSS 5.1
CVE-2006-3743 [MEDIUM] CVE-2006-3743: Multiple buffer overflows in ImageMagick before 6
Multiple buffer overflows in ImageMagick before 6.2.9 allow user-assisted attackers to execute arbitrary code via crafted XCF images.
Ubuntu
imagemagick vulnerabilities
vendor_ubuntu·2006-09-06
CVE-2006-3743 imagemagick vulnerabilities
Title: imagemagick vulnerabilities
Summary: imagemagick vulnerabilities
Tavis Ormandy discovered several buffer overflows in imagemagick's Sun
Raster and XCF (Gimp) image decoders. By tricking a user or automated
system into processing a specially crafted image, this could be
exploited to execute arbitrary code with the users' privileges.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
security flaw
vendor_redhat·2006-08-22·CVSS 5.1
CVE-2006-3743 [MEDIUM] security flaw
security flaw
Multiple buffer overflows in ImageMagick before 6.2.9 allow user-assisted attackers to execute arbitrary code via crafted XCF images.
Statement: Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Debian
CVE-2006-3743: graphicsmagick - Multiple buffer overflows in ImageMagick before 6.2.9 allow user-assisted attack...
vendor_debian·2006·CVSS 5.1
CVE-2006-3743 [MEDIUM] CVE-2006-3743: graphicsmagick - Multiple buffer overflows in ImageMagick before 6.2.9 allow user-assisted attack...
Multiple buffer overflows in ImageMagick before 6.2.9 allow user-assisted attackers to execute arbitrary code via crafted XCF images.
Scope: local
bookworm: resolved (fixed in 1.1.7-8)
bullseye: resolved (fixed in 1.1.7-8)
forky: resolved (fixed in 1.1.7-8)
sid: resolved (fixed in 1.1.7-8)
trixie: resolved (fixed in 1.1.7-8)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-3743 security flaw
bugzilla·2018-08-16·CVSS 5.1
CVE-2006-3743 [MEDIUM] CVE-2006-3743 security flaw
CVE-2006-3743 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Multiple buffer overflows in ImageMagick before 6.2.9 allow user-assisted attackers to execute arbitrary code via crafted XCF images.
---
Statement:
Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Bugzilla
CVE-2006-3743 ImageMagick multiple security issues (CVE-2006-3744)
bugzilla·2006-08-11·CVSS 5.1
CVE-2006-3743 [MEDIUM] CVE-2006-3743 ImageMagick multiple security issues (CVE-2006-3744)
CVE-2006-3743 ImageMagick multiple security issues (CVE-2006-3744)
Tavis Ormandy, Google Security Team, told us about several integer and buffer
overflow flaws in ImageMagick. These flaws are present in ImageMagick's sun
bitmap decoder and the xcf decoder.
Discussion:
These issues also affect RHEL2 and RHEL3
---
Created attachment 134022
Proposed patch from Tavis
---
I have created a RHTS testcase with the demo images, and I have
built
ImageMagick-5.3.8-15 (RHEL2.1)
ImageMagick-5.5.6-19 (RHEL3)
ImageMagick-6.0.7.1-15 (RHEL4)
with the fix.
Note that I had no chance to verify the testcase or test the fix yet, since RHTS
is down.
---
This errata will be RHSA-2006:0633
---
An advisory has been issued which should help the problem
described in this bug report. This report is there
Bugzilla
CVE-2006-0082 ImageMagick format string vulnerability. Also CVE-2005-4601, CVE-2006-2440, CVE-2006-3743, CVE-2006-3744, CVE-2006-4144.
bugzilla·2006-01-04·CVSS 7.5
CVE-2006-0082 [HIGH] CVE-2006-0082 ImageMagick format string vulnerability. Also CVE-2005-4601, CVE-2006-2440, CVE-2006-3743, CVE-2006-3744, CVE-2006-4144.
CVE-2006-0082 ImageMagick format string vulnerability. Also CVE-2005-4601, CVE-2006-2440, CVE-2006-3743, CVE-2006-3744, CVE-2006-4144.
ImageMagick format string vulnerability.
The fix for CVE-2005-0397 is incomplete. As the Debian bug suggests,
by running a command such as:
convert file.jpg file%d%n.jpg
A segfault will result in ImageMagick.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345876
Discussion:
From User-Agent: XML-RPC
ImageMagick-6.2.2.0-3.fc4.1 has been pushed for FC4, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report.
---
I see updates have been released for FC4 - any chance to get the fixes applied
to FC3 as well? I know it has been transfered to legacy - however
security-support
ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.aschttp://bugs.gentoo.org/show_bug.cgi?id=144854http://secunia.com/advisories/21615http://secunia.com/advisories/21621http://secunia.com/advisories/21671http://secunia.com/advisories/21679http://secunia.com/advisories/21719http://secunia.com/advisories/21780http://secunia.com/advisories/21832http://secunia.com/advisories/22036http://secunia.com/advisories/22096http://security.gentoo.org/glsa/glsa-200609-14.xmlhttp://securitytracker.com/id?1016749http://www.debian.org/security/2006/dsa-1168http://www.mandriva.com/security/advisories?name=MDKSA-2006:155http://www.novell.com/linux/security/advisories/2006_50_imagemagick.htmlhttp://www.osvdb.org/28205http://www.redhat.com/support/errata/RHSA-2006-0633.htmlhttp://www.securityfocus.com/bid/19697http://www.ubuntu.com/usn/usn-340-1http://www.vupen.com/english/advisories/2006/3375https://exchange.xforce.ibmcloud.com/vulnerabilities/28575https://issues.rpath.com/browse/RPL-605https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9895ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.aschttp://bugs.gentoo.org/show_bug.cgi?id=144854http://secunia.com/advisories/21615http://secunia.com/advisories/21621http://secunia.com/advisories/21671http://secunia.com/advisories/21679http://secunia.com/advisories/21719http://secunia.com/advisories/21780http://secunia.com/advisories/21832http://secunia.com/advisories/22036http://secunia.com/advisories/22096http://security.gentoo.org/glsa/glsa-200609-14.xmlhttp://securitytracker.com/id?1016749http://www.debian.org/security/2006/dsa-1168http://www.mandriva.com/security/advisories?name=MDKSA-2006:155http://www.novell.com/linux/security/advisories/2006_50_imagemagick.htmlhttp://www.osvdb.org/28205http://www.redhat.com/support/errata/RHSA-2006-0633.htmlhttp://www.securityfocus.com/bid/19697http://www.ubuntu.com/usn/usn-340-1http://www.vupen.com/english/advisories/2006/3375https://exchange.xforce.ibmcloud.com/vulnerabilities/28575https://issues.rpath.com/browse/RPL-605https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9895
2006-08-25
Published