CVE-2007-0770Improper Restriction of Operations within the Bounds of a Memory Buffer in Graphicsmagick

Severity
9.3CRITICALNVD
OSV5.1
EPSS
7.1%
top 8.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 12
Latest updateMay 17

Description

Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c. NOTE: this issue is due to an incomplete patch for CVE-2006-5456.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages6 packages

debiandebian/imagemagick< graphicsmagick 1.1.7-12 (bookworm)
Debianimagemagick/imagemagick< 7:6.2.4.5.dfsg1-0.14+3
debiandebian/graphicsmagick< graphicsmagick 1.2.3-1 (bookworm)+1
Debiangraphicsmagick/graphicsmagick< 1.1.7-12+7

🔴Vulnerability Details

4
GHSA
GHSA-vwj5-vw48-r26j: Multiple heap-based buffer underflows in the ReadPALMImage function in coders/palm2022-05-17
GHSA
GHSA-94w9-jj9w-mx3v: Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary co2022-05-01
OSV
CVE-2008-6070: Multiple heap-based buffer underflows in the ReadPALMImage function in coders/palm2009-02-10
OSV
CVE-2007-0770: Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary co2007-02-12

📋Vendor Advisories

5
Debian
CVE-2008-6070: graphicsmagick - Multiple heap-based buffer underflows in the ReadPALMImage function in coders/pa...2008
Red Hat
, CVE-2008-6071, CVE-2008-6072, CVE-2008-6621 multiple security issues in ImageMagick2007-03-01
Ubuntu
ImageMagick vulnerabilities2007-02-15
Debian
CVE-2007-0770: graphicsmagick - Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote at...2007
Red Hat
CVE-2007-0770: GraphicsMagick buffer overflow

💬Community

2
Bugzilla
CVE-2007-0770: GraphicsMagick buffer overflow2007-02-14
Bugzilla
CVE-2006-5456 Overflows in GraphicsMagick and ImageMagick's DCM and PALM handling routines2006-10-16