CVE-2007-4985Infinite Loop in Imagemagick

Severity
4.3MEDIUMNVD
EPSS
2.8%
top 13.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 24
Latest updateMay 1

Description

ImageMagick before 6.3.5-9 allows context-dependent attackers to cause a denial of service via a crafted image file that triggers (1) an infinite loop in the ReadDCMImage function, related to ReadBlobByte function calls; or (2) an infinite loop in the ReadXCFImage function, related to ReadBlobMSBLong function calls.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages5 packages

debiandebian/imagemagick< graphicsmagick 1.1.11-1 (bookworm)
Debianimagemagick/imagemagick< 7:6.2.4.5.dfsg1-2+3
NVDimagemagick/imagemagick57 versions+56
debiandebian/graphicsmagick< graphicsmagick 1.1.11-1 (bookworm)
Debiangraphicsmagick/graphicsmagick< 1.1.11-1+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-fxg4-75m7-4xj5: ImageMagick before 62022-05-01
OSV
CVE-2007-4985: ImageMagick before 62007-09-24

📋Vendor Advisories

3
Ubuntu
ImageMagick vulnerabilities2007-10-03
Red Hat
Infinite loops in ImageMagick's XCF and DCM coders2007-09-19
Debian
CVE-2007-4985: graphicsmagick - ImageMagick before 6.3.5-9 allows context-dependent attackers to cause a denial ...2007

💬Community

1
Bugzilla
CVE-2007-4985 Infinite loops in ImageMagick's XCF and DCM coders2007-09-27