CVE-2007-1797
published 2007-04-02CVE-2007-1797: Multiple integer overflows in ImageMagick before 6.3.3-5 allow remote attackers to execute arbitrary code via (1) a crafted DCM image, which results in a…
PriorityP431medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.53%
88.0th percentile
Multiple integer overflows in ImageMagick before 6.3.3-5 allow remote attackers to execute arbitrary code via (1) a crafted DCM image, which results in a heap-based overflow in the ReadDCMImage function, or (2) the (a) colors or (b) comments field in a crafted XWD image, which results in a heap-based overflow in the ReadXWDImage function, different issues than CVE-2007-1667.
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | graphicsmagick | < graphicsmagick 1.1.7-15 (bookworm) | graphicsmagick 1.1.7-15 (bookworm) |
| debian | imagemagick | < graphicsmagick 1.1.7-15 (bookworm) | graphicsmagick 1.1.7-15 (bookworm) |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.7-15 | 1.1.7-15 |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.7-15 | 1.1.7-15 |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.7-15 | 1.1.7-15 |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.7-15 | 1.1.7-15 |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.3CRITICAL
vendor_debian9.3MEDIUM
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r8m6-cvrj-9326: Multiple integer overflows in ImageMagick before 6
ghsa_unreviewed·2022-05-01·CVSS 9.3
CVE-2007-1797 [CRITICAL] GHSA-r8m6-cvrj-9326: Multiple integer overflows in ImageMagick before 6
Multiple integer overflows in ImageMagick before 6.3.3-5 allow remote attackers to execute arbitrary code via (1) a crafted DCM image, which results in a heap-based overflow in the ReadDCMImage function, or (2) the (a) colors or (b) comments field in a crafted XWD image, which results in a heap-based overflow in the ReadXWDImage function, different issues than CVE-2007-1667.
OSV
CVE-2007-1797: Multiple integer overflows in ImageMagick before 6
osv·2007-04-02·CVSS 9.3
CVE-2007-1797 [CRITICAL] CVE-2007-1797: Multiple integer overflows in ImageMagick before 6
Multiple integer overflows in ImageMagick before 6.3.3-5 allow remote attackers to execute arbitrary code via (1) a crafted DCM image, which results in a heap-based overflow in the ReadDCMImage function, or (2) the (a) colors or (b) comments field in a crafted XWD image, which results in a heap-based overflow in the ReadXWDImage function, different issues than CVE-2007-1667.
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2007-07-10
CVE-2007-1667 ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: ImageMagick vulnerabilities
Multiple vulnerabilities were found in ImageMagick's handling of DCM and
WXD image files. By tricking a user into processing a specially crafted
image with an application that uses imagemagick, an attacker could
execute arbitrary code with the user's privileges.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
Heap overflow in ImageMagick's DCM and XWD coders
vendor_redhat·2007-03-31·CVSS 9.3
CVE-2007-1797 [CRITICAL] Heap overflow in ImageMagick's DCM and XWD coders
Heap overflow in ImageMagick's DCM and XWD coders
Multiple integer overflows in ImageMagick before 6.3.3-5 allow remote attackers to execute arbitrary code via (1) a crafted DCM image, which results in a heap-based overflow in the ReadDCMImage function, or (2) the (a) colors or (b) comments field in a crafted XWD image, which results in a heap-based overflow in the ReadXWDImage function, different issues than CVE-2007-1667.
Debian
CVE-2007-1797: graphicsmagick - Multiple integer overflows in ImageMagick before 6.3.3-5 allow remote attackers ...
vendor_debian·2007·CVSS 9.3
CVE-2007-1797 [CRITICAL] CVE-2007-1797: graphicsmagick - Multiple integer overflows in ImageMagick before 6.3.3-5 allow remote attackers ...
Multiple integer overflows in ImageMagick before 6.3.3-5 allow remote attackers to execute arbitrary code via (1) a crafted DCM image, which results in a heap-based overflow in the ReadDCMImage function, or (2) the (a) colors or (b) comments field in a crafted XWD image, which results in a heap-based overflow in the ReadXWDImage function, different issues than CVE-2007-1667.
Scope: local
bookworm: resolved (fixed in 1.1.7-15)
bullseye: resolved (fixed in 1.1.7-15)
forky: resolved (fixed in 1.1.7-15)
sid: resolved (fixed in 1.1.7-15)
trixie: resolved (fixed in 1.1.7-15)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-6070, CVE-2008-6071, CVE-2008-6072, CVE-2008-6621 multiple security issues in ImageMagick
bugzilla·2009-08-07·CVSS 9.3
CVE-2008-6070 [CRITICAL] CVE-2008-6070, CVE-2008-6071, CVE-2008-6072, CVE-2008-6621 multiple security issues in ImageMagick
CVE-2008-6070, CVE-2008-6071, CVE-2008-6072, CVE-2008-6621 multiple security issues in ImageMagick
There are a number of unresolved security/crasher issues in ImageMagick that has been tedious to track down. Only a few of these issues are security-related, and even then would have low or moderate impact at best. Others are not security related. This bug corresponds to bug #476551 mostly.
Discussion:
Created attachment 357055
corrects broken2.bmp segfault on rhel4
---
Created attachment 357056
corrects broken.cin segfault on rhel4
---
Created attachment 357057
corrects broken/broken2.sgi segfaults on rhel4
---
I have backported the above first to RHEL5, and although they applied, they weren't necessary as there were no segfaults there to begin with. However, if these are essentiall
Bugzilla
CVE-2007-1797 Heap overflow in ImageMagick's DCM and XWD coders
bugzilla·2007-04-03·CVSS 6.8
CVE-2007-1797 [MEDIUM] CVE-2007-1797 Heap overflow in ImageMagick's DCM and XWD coders
CVE-2007-1797 Heap overflow in ImageMagick's DCM and XWD coders
Description of problem:
According to an iDefense advisory (see the URL), ImageMagick is vulnerable
to heap overflow flaws that can be triggered with crafted DCM and XWD files
and exploited to execute arbitrary code.
Version-Release number of selected component (if applicable):
FC6 (6.2.8.0-3.fc6.1)
FC5 (6.2.5.4-4.2.1.fc5.7)
RHEL5 (6.2.8.0-3.el5.4)
RHEL4 (6.0.7.1-17)
RHEL3 (5.5.6-25)
RHEL2.1 (5.3.8-18)
How reproducible:
Reproducers are not available at the time.
Additional info:
There are actually three bugs, one in DCM coder and two in XWD.
I attach my attempt to backport the fixes.
Discussion:
Created attachment 151594
Fix for CVE-2007-1797 ImageMagick's DCM and XWD (RHEL-4, RHEL-5, FC-5 and FC-6)
---
Created atta
Bugzilla
CVE-2007-1797 Heap overflow in ImageMagick's DCM and XWD coders
bugzilla·2007-04-03·CVSS 6.8
CVE-2007-1797 [MEDIUM] CVE-2007-1797 Heap overflow in ImageMagick's DCM and XWD coders
CVE-2007-1797 Heap overflow in ImageMagick's DCM and XWD coders
+++ This bug was initially created as a clone of Bug #235071 +++
Description of problem:
According to an iDefense advisory (see the URL), ImageMagick is vulnerable
to heap overflow flaws that can be triggered with crafted DCM and XWD files
and exploited to execute arbitrary code.
Version-Release number of selected component (if applicable):
FC6 (6.2.8.0-3.fc6.1)
FC5 (6.2.5.4-4.2.1.fc5.7)
RHEL5 (6.2.8.0-3.el5.4)
RHEL4 (6.0.7.1-17)
RHEL3 (5.5.6-25)
RHEL2.1 (5.3.8-18)
How reproducible:
Reproducers are not available at the time.
Additional info:
There are actually three bugs, one in DCM coder and two in XWD.
I attach my attempt to backport the fixes.
-- Additional comment from [email protected] on 2007-04-03 14:07 EST
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=496http://secunia.com/advisories/24721http://secunia.com/advisories/24739http://secunia.com/advisories/25072http://secunia.com/advisories/25206http://secunia.com/advisories/25992http://secunia.com/advisories/26177http://secunia.com/advisories/29786http://secunia.com/advisories/29857http://secunia.com/advisories/36260http://security.gentoo.org/glsa/glsa-200705-13.xmlhttp://www.debian.org/security/2009/dsa-1858http://www.imagemagick.org/script/changelog.phphttp://www.mandriva.com/security/advisories?name=MDKSA-2007:147http://www.novell.com/linux/security/advisories/2007_8_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0145.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0165.htmlhttp://www.securityfocus.com/bid/23252http://www.securityfocus.com/bid/23347http://www.securitytracker.com/id?1017839http://www.ubuntu.com/usn/usn-481-1http://www.vupen.com/english/advisories/2007/1200https://exchange.xforce.ibmcloud.com/vulnerabilities/33376https://exchange.xforce.ibmcloud.com/vulnerabilities/33377https://issues.foresightlinux.org/browse/FL-222https://issues.rpath.com/browse/RPL-1205https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9254http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=496http://secunia.com/advisories/24721http://secunia.com/advisories/24739http://secunia.com/advisories/25072http://secunia.com/advisories/25206http://secunia.com/advisories/25992http://secunia.com/advisories/26177http://secunia.com/advisories/29786http://secunia.com/advisories/29857http://secunia.com/advisories/36260http://security.gentoo.org/glsa/glsa-200705-13.xmlhttp://www.debian.org/security/2009/dsa-1858http://www.imagemagick.org/script/changelog.phphttp://www.mandriva.com/security/advisories?name=MDKSA-2007:147http://www.novell.com/linux/security/advisories/2007_8_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0145.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0165.htmlhttp://www.securityfocus.com/bid/23252http://www.securityfocus.com/bid/23347http://www.securitytracker.com/id?1017839http://www.ubuntu.com/usn/usn-481-1http://www.vupen.com/english/advisories/2007/1200https://exchange.xforce.ibmcloud.com/vulnerabilities/33376https://exchange.xforce.ibmcloud.com/vulnerabilities/33377https://issues.foresightlinux.org/browse/FL-222https://issues.rpath.com/browse/RPL-1205https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9254
2007-04-02
Published