CVE-2008-1096
published 2008-03-05CVE-2008-1096: The load_tile function in the XCF coder in coders/xcf.c in (1) ImageMagick 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers…
PriorityP430medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.53%
90.5th percentile
The load_tile function in the XCF coder in coders/xcf.c in (1) ImageMagick 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .xcf file that triggers an out-of-bounds heap write, possibly related to the ScaleCharToQuantum function.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | graphicsmagick | < graphicsmagick 1.1.11-3.2 (bookworm) | graphicsmagick 1.1.11-3.2 (bookworm) |
| debian | imagemagick | < graphicsmagick 1.1.11-3.2 (bookworm) | graphicsmagick 1.1.11-3.2 (bookworm) |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.11-3.2 | 1.1.11-3.2 |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.11-3.2 | 1.1.11-3.2 |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.11-3.2 | 1.1.11-3.2 |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.11-3.2 | 1.1.11-3.2 |
| imagemagick | graphicsmagick | — | — |
| imagemagick | graphicsmagick | — | — |
| imagemagick | graphicsmagick | — | — |
| imagemagick | graphicsmagick | — | — |
| imagemagick | graphicsmagick | — | — |
| imagemagick | graphicsmagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | >= 0 < 7:6.3.7.9.dfsg1-2.1 | 7:6.3.7.9.dfsg1-2.1 |
| imagemagick | imagemagick | >= 0 < 7:6.3.7.9.dfsg1-2.1 | 7:6.3.7.9.dfsg1-2.1 |
| imagemagick | imagemagick | >= 0 < 7:6.3.7.9.dfsg1-2.1 | 7:6.3.7.9.dfsg1-2.1 |
| imagemagick | imagemagick | >= 0 < 7:6.3.7.9.dfsg1-2.1 | 7:6.3.7.9.dfsg1-2.1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ImageMagick vulnerability
vendor_ubuntu·2008-12-01
CVE-2008-1096 ImageMagick vulnerability
Title: ImageMagick vulnerability
Summary: ImageMagick vulnerability
It was discovered that ImageMagick did not correctly handle certain
malformed XCF images. If a user were tricked into opening a specially
crafted image with an application that uses ImageMagick, an attacker
could cause a denial of service and possibly execute arbitrary code with
the user's privileges.
Instructions: After a standard system upgrade you need to restart any applications that
use ImageMagick, such as OpenOffice.org and Inkscape, to effect the
necessary changes.
Debian
CVE-2008-1096: graphicsmagick - The load_tile function in the XCF coder in coders/xcf.c in (1) ImageMagick 6.2.8...
vendor_debian·2008·CVSS 6.8
CVE-2008-1096 [MEDIUM] CVE-2008-1096: graphicsmagick - The load_tile function in the XCF coder in coders/xcf.c in (1) ImageMagick 6.2.8...
The load_tile function in the XCF coder in coders/xcf.c in (1) ImageMagick 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .xcf file that triggers an out-of-bounds heap write, possibly related to the ScaleCharToQuantum function.
Scope: local
bookworm: resolved (fixed in 1.1.11-3.2)
bullseye: resolved (fixed in 1.1.11-3.2)
forky: resolved (fixed in 1.1.11-3.2)
sid: resolved (fixed in 1.1.11-3.2)
trixie: resolved (fixed in 1.1.11-3.2)
Red Hat
Out of bound write in ImageMagick's XCF coder
vendor_redhat·2007-03-11·CVSS 6.8
CVE-2008-1096 [MEDIUM] Out of bound write in ImageMagick's XCF coder
Out of bound write in ImageMagick's XCF coder
The load_tile function in the XCF coder in coders/xcf.c in (1) ImageMagick 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .xcf file that triggers an out-of-bounds heap write, possibly related to the ScaleCharToQuantum function.
GHSA
GHSA-q243-329x-qc2r: The load_tile function in the XCF coder in coders/xcf
ghsa_unreviewed·2022-05-01
CVE-2008-1096 [MEDIUM] CWE-119 GHSA-q243-329x-qc2r: The load_tile function in the XCF coder in coders/xcf
The load_tile function in the XCF coder in coders/xcf.c in (1) ImageMagick 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .xcf file that triggers an out-of-bounds heap write, possibly related to the ScaleCharToQuantum function.
OSV
CVE-2008-1096: The load_tile function in the XCF coder in coders/xcf
osv·2008-03-05·CVSS 6.8
CVE-2008-1096 [MEDIUM] CVE-2008-1096: The load_tile function in the XCF coder in coders/xcf
The load_tile function in the XCF coder in coders/xcf.c in (1) ImageMagick 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .xcf file that triggers an out-of-bounds heap write, possibly related to the ScaleCharToQuantum function.
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=414370http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.htmlhttp://osvdb.org/43212http://secunia.com/advisories/29786http://secunia.com/advisories/30967http://secunia.com/advisories/32945http://secunia.com/advisories/36260http://www.debian.org/security/2009/dsa-1858http://www.mandriva.com/security/advisories?name=MDVSA-2008:099http://www.redhat.com/support/errata/RHSA-2008-0145.htmlhttp://www.securityfocus.com/bid/28821http://www.securitytracker.com/id?1019880http://www.ubuntu.com/usn/USN-681-1https://bugzilla.redhat.com/show_bug.cgi?id=286411https://exchange.xforce.ibmcloud.com/vulnerabilities/41194https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10843http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=414370http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.htmlhttp://osvdb.org/43212http://secunia.com/advisories/29786http://secunia.com/advisories/30967http://secunia.com/advisories/32945http://secunia.com/advisories/36260http://www.debian.org/security/2009/dsa-1858http://www.mandriva.com/security/advisories?name=MDVSA-2008:099http://www.redhat.com/support/errata/RHSA-2008-0145.htmlhttp://www.securityfocus.com/bid/28821http://www.securitytracker.com/id?1019880http://www.ubuntu.com/usn/USN-681-1https://bugzilla.redhat.com/show_bug.cgi?id=286411https://exchange.xforce.ibmcloud.com/vulnerabilities/41194https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10843
2008-03-05
Published