cbcvebase.
CVE-2006-5456
published 2006-10-23

CVE-2006-5456: Multiple buffer overflows in GraphicsMagick before 1.1.7 and ImageMagick 6.0.7 allow user-assisted attackers to cause a denial of service and possibly execute…

PriorityP424medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
3.57%
88.2th percentile
Multiple buffer overflows in GraphicsMagick before 1.1.7 and ImageMagick 6.0.7 allow user-assisted attackers to cause a denial of service and possibly execute arbitrary code via (1) a DCM image that is not properly handled by the ReadDCMImage function in coders/dcm.c, or (2) a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debiangraphicsmagick< graphicsmagick 1.1.7-9 (bookworm)graphicsmagick 1.1.7-9 (bookworm)
debiangraphicsmagick< graphicsmagick 1.1.7-12 (bookworm)graphicsmagick 1.1.7-12 (bookworm)
debianimagemagick< graphicsmagick 1.1.7-9 (bookworm)graphicsmagick 1.1.7-9 (bookworm)
debianimagemagick< graphicsmagick 1.1.7-12 (bookworm)graphicsmagick 1.1.7-12 (bookworm)
graphicsmagickgraphicsmagick<= 1.1.6
graphicsmagickgraphicsmagick
graphicsmagickgraphicsmagick
graphicsmagickgraphicsmagick
graphicsmagickgraphicsmagick
graphicsmagickgraphicsmagick
graphicsmagickgraphicsmagick
graphicsmagickgraphicsmagick>= 0 < 1.1.7-91.1.7-9
graphicsmagickgraphicsmagick>= 0 < 1.1.7-121.1.7-12
graphicsmagickgraphicsmagick>= 0 < 1.1.7-91.1.7-9
graphicsmagickgraphicsmagick>= 0 < 1.1.7-121.1.7-12
graphicsmagickgraphicsmagick>= 0 < 1.1.7-91.1.7-9
graphicsmagickgraphicsmagick>= 0 < 1.1.7-121.1.7-12
graphicsmagickgraphicsmagick>= 0 < 1.1.7-91.1.7-9
graphicsmagickgraphicsmagick>= 0 < 1.1.7-121.1.7-12
imagemagickimagemagick
imagemagickimagemagick
imagemagickimagemagick>= 0 < 7:6.2.4.5.dfsg1-0.117:6.2.4.5.dfsg1-0.11
imagemagickimagemagick>= 0 < 7:6.2.4.5.dfsg1-0.147:6.2.4.5.dfsg1-0.14
imagemagickimagemagick>= 0 < 7:6.2.4.5.dfsg1-0.117:6.2.4.5.dfsg1-0.11
imagemagickimagemagick>= 0 < 7:6.2.4.5.dfsg1-0.147:6.2.4.5.dfsg1-0.14

CVSS provenance

nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv5.1MEDIUM
vendor_debian5.1MEDIUM
vendor_redhat5.1MEDIUM
vendor_ubuntu5.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.