CVE-2007-4987
published 2007-09-24CVE-2007-4987: Off-by-one error in the ReadBlobString function in blob.c in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a…
PriorityP336critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.82%
89.0th percentile
Off-by-one error in the ReadBlobString function in blob.c in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted image file, which triggers the writing of a '\0' character to an out-of-bounds address.
Affected
62 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imagemagick | < imagemagick 7:6.2.4.5.dfsg1-2 (bookworm) | imagemagick 7:6.2.4.5.dfsg1-2 (bookworm) |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3MEDIUM
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2007-10-03
CVE-2007-4985 ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: ImageMagick vulnerabilities
Multiple vulnerabilities were found in the image decoders of ImageMagick.
If a user or automated system were tricked into processing a malicious
DCM, DIB, XBM, XCF, or XWD image, a remote attacker could execute arbitrary
code with user privileges.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
ImageMagick writes terminating NUL one byte beyond char array end
vendor_redhat·2007-09-19·CVSS 9.3
CVE-2007-4987 [CRITICAL] ImageMagick writes terminating NUL one byte beyond char array end
ImageMagick writes terminating NUL one byte beyond char array end
Off-by-one error in the ReadBlobString function in blob.c in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted image file, which triggers the writing of a '\0' character to an out-of-bounds address.
Statement: Note: As the address of the overwritten byte is not under attackers control, the worst impact his bug could have is an application crash. It can not be exploited to execute arbitrary code.
Debian
CVE-2007-4987: imagemagick - Off-by-one error in the ReadBlobString function in blob.c in ImageMagick before ...
vendor_debian·2007·CVSS 9.3
CVE-2007-4987 [CRITICAL] CVE-2007-4987: imagemagick - Off-by-one error in the ReadBlobString function in blob.c in ImageMagick before ...
Off-by-one error in the ReadBlobString function in blob.c in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted image file, which triggers the writing of a '\0' character to an out-of-bounds address.
Scope: local
bookworm: resolved (fixed in 7:6.2.4.5.dfsg1-2)
bullseye: resolved (fixed in 7:6.2.4.5.dfsg1-2)
forky: resolved (fixed in 7:6.2.4.5.dfsg1-2)
sid: resolved (fixed in 7:6.2.4.5.dfsg1-2)
trixie: resolved (fixed in 7:6.2.4.5.dfsg1-2)
GHSA
GHSA-8r4q-vv4v-f978: Off-by-one error in the ReadBlobString function in blob
ghsa_unreviewed·2022-05-01
CVE-2007-4987 [HIGH] GHSA-8r4q-vv4v-f978: Off-by-one error in the ReadBlobString function in blob
Off-by-one error in the ReadBlobString function in blob.c in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted image file, which triggers the writing of a '\0' character to an out-of-bounds address.
OSV
CVE-2007-4987: Off-by-one error in the ReadBlobString function in blob
osv·2007-09-24·CVSS 9.3
CVE-2007-4987 [CRITICAL] CVE-2007-4987: Off-by-one error in the ReadBlobString function in blob
Off-by-one error in the ReadBlobString function in blob.c in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted image file, which triggers the writing of a '\0' character to an out-of-bounds address.
No detection rules found.
No public exploits indexed.
http://bugs.gentoo.org/show_bug.cgi?id=186030http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=595http://secunia.com/advisories/26926http://secunia.com/advisories/27048http://secunia.com/advisories/27309http://secunia.com/advisories/27364http://secunia.com/advisories/27439http://secunia.com/advisories/28721http://secunia.com/advisories/36260http://security.gentoo.org/glsa/glsa-200710-27.xmlhttp://studio.imagemagick.org/pipermail/magick-announce/2007-September/000037.htmlhttp://www.debian.org/security/2009/dsa-1858http://www.imagemagick.org/script/changelog.phphttp://www.mandriva.com/en/security/advisories?name=MDVSA-2008:035http://www.novell.com/linux/security/advisories/2007_23_sr.htmlhttp://www.securityfocus.com/archive/1/483572/100/0/threadedhttp://www.securityfocus.com/bid/25766http://www.securitytracker.com/id?1018729http://www.ubuntu.com/usn/usn-523-1http://www.vupen.com/english/advisories/2007/3245https://exchange.xforce.ibmcloud.com/vulnerabilities/36739https://issues.rpath.com/browse/RPL-1743http://bugs.gentoo.org/show_bug.cgi?id=186030http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=595http://secunia.com/advisories/26926http://secunia.com/advisories/27048http://secunia.com/advisories/27309http://secunia.com/advisories/27364http://secunia.com/advisories/27439http://secunia.com/advisories/28721http://secunia.com/advisories/36260http://security.gentoo.org/glsa/glsa-200710-27.xmlhttp://studio.imagemagick.org/pipermail/magick-announce/2007-September/000037.htmlhttp://www.debian.org/security/2009/dsa-1858http://www.imagemagick.org/script/changelog.phphttp://www.mandriva.com/en/security/advisories?name=MDVSA-2008:035http://www.novell.com/linux/security/advisories/2007_23_sr.htmlhttp://www.securityfocus.com/archive/1/483572/100/0/threadedhttp://www.securityfocus.com/bid/25766http://www.securitytracker.com/id?1018729http://www.ubuntu.com/usn/usn-523-1http://www.vupen.com/english/advisories/2007/3245https://exchange.xforce.ibmcloud.com/vulnerabilities/36739https://issues.rpath.com/browse/RPL-1743
2007-09-24
Published