CVE-2008-1097Out-of-bounds Write in Graphicsmagick

CWE-3996 documents6 sources
Severity
6.8MEDIUMNVD
EPSS
6.2%
top 9.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 5
Latest updateMay 1

Description

Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx.c in (1) ImageMagick 6.2.4-5 and 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .pcx file that triggers incorrect memory allocation for the scanline array, leading to memory corruption.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages6 packages

NVDimagemagick/graphicsmagick6 versions+5
debiandebian/imagemagick< graphicsmagick 1.1.7-13 (bookworm)
debiandebian/graphicsmagick< graphicsmagick 1.1.7-13 (bookworm)
Debianimagemagick/imagemagick< 7:6.2.4.5.dfsg1-1+3
Debiangraphicsmagick/graphicsmagick< 1.1.7-13+3

🔴Vulnerability Details

2
GHSA
GHSA-w4vc-7rfv-99f6: Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx2022-05-01
OSV
CVE-2008-1097: Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx2008-03-05

📋Vendor Advisories

2
Debian
CVE-2008-1097: graphicsmagick - Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in code...2008
Red Hat
Memory corruption in ImageMagick's PCX coder2007-03-11

💬Community

1
Bugzilla
CVE-2008-1097 Memory corruption in ImageMagick's PCX coder2007-09-11