CVE-2006-3743Improper Restriction of Operations within the Bounds of a Memory Buffer in Imagemagick

9 documents7 sources
Severity
5.1MEDIUMNVD
EPSS
2.1%
top 15.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 25
Latest updateMay 3

Description

Multiple buffer overflows in ImageMagick before 6.2.9 allow user-assisted attackers to execute arbitrary code via crafted XCF images.

CVSS vector

AV:N/AC:H/C:P/I:P/A:PExploitability: 4.9 | Impact: 6.4

Affected Packages5 packages

debiandebian/imagemagick< graphicsmagick 1.1.7-8 (bookworm)
Debianimagemagick/imagemagick< 7:6.2.4.5.dfsg1-0.10+3
NVDimagemagick/imagemagick16 versions+15
debiandebian/graphicsmagick< graphicsmagick 1.1.7-8 (bookworm)
Debiangraphicsmagick/graphicsmagick< 1.1.7-8+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vwf7-7g8c-h7pw: Multiple buffer overflows in ImageMagick before 62022-05-03
OSV
CVE-2006-3743: Multiple buffer overflows in ImageMagick before 62006-08-25

📋Vendor Advisories

3
Ubuntu
imagemagick vulnerabilities2006-09-06
Red Hat
security flaw2006-08-22
Debian
CVE-2006-3743: graphicsmagick - Multiple buffer overflows in ImageMagick before 6.2.9 allow user-assisted attack...2006

💬Community

3
Bugzilla
CVE-2006-3743 security flaw2018-08-16
Bugzilla
CVE-2006-3743 ImageMagick multiple security issues (CVE-2006-3744)2006-08-11
Bugzilla
CVE-2006-0082 ImageMagick format string vulnerability. Also CVE-2005-4601, CVE-2006-2440, CVE-2006-3743, CVE-2006-3744, CVE-2006-4144.2006-01-04