CVE-2006-5456Improper Restriction of Operations within the Bounds of a Memory Buffer in Graphicsmagick

Severity
9.3CRITICALNVD
NVD5.1OSV5.1
EPSS
0.9%
top 25.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 23
Latest updateMay 3

Description

Multiple buffer overflows in GraphicsMagick before 1.1.7 and ImageMagick 6.0.7 allow user-assisted attackers to cause a denial of service and possibly execute arbitrary code via (1) a DCM image that is not properly handled by the ReadDCMImage function in coders/dcm.c, or (2) a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c.

CVSS vector

AV:N/AC:H/C:P/I:P/A:PExploitability: 4.9 | Impact: 6.4

Affected Packages6 packages

debiandebian/imagemagick< graphicsmagick 1.1.7-9 (bookworm)+1
Debianimagemagick/imagemagick< 7:6.2.4.5.dfsg1-0.11+7
NVDimagemagick/imagemagick6.0.7, 6.3.3.4+1
debiandebian/graphicsmagick< graphicsmagick 1.1.7-9 (bookworm)+1
Debiangraphicsmagick/graphicsmagick< 1.1.7-9+7

Patches

🔴Vulnerability Details

4
GHSA
GHSA-cfvq-2qp7-r72f: Multiple buffer overflows in GraphicsMagick before 12022-05-03
GHSA
GHSA-94w9-jj9w-mx3v: Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary co2022-05-01
OSV
CVE-2007-0770: Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary co2007-02-12
OSV
CVE-2006-5456: Multiple buffer overflows in GraphicsMagick before 12006-10-23

📋Vendor Advisories

6
Ubuntu
ImageMagick vulnerabilities2007-02-15
Debian
CVE-2007-0770: graphicsmagick - Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote at...2007
Ubuntu
imagemagick vulnerability2006-11-01
Red Hat
Overflows in GraphicsMagick and ImageMagick's DCM and PALM handling routines2006-09-29
Debian
CVE-2006-5456: graphicsmagick - Multiple buffer overflows in GraphicsMagick before 1.1.7 and ImageMagick 6.0.7 a...2006

💬Community

2
Bugzilla
CVE-2007-0770: GraphicsMagick buffer overflow2007-02-14
Bugzilla
CVE-2006-5456 Overflows in GraphicsMagick and ImageMagick's DCM and PALM handling routines2006-10-16