CVE-2008-1097
published 2008-03-05CVE-2008-1097: Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx.c in (1) ImageMagick 6.2.4-5 and 6.2.8-0 and (2) GraphicsMagick (aka gm)…
PriorityP433medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.48%
90.5th percentile
Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx.c in (1) ImageMagick 6.2.4-5 and 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .pcx file that triggers incorrect memory allocation for the scanline array, leading to memory corruption.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | graphicsmagick | < graphicsmagick 1.1.7-13 (bookworm) | graphicsmagick 1.1.7-13 (bookworm) |
| debian | imagemagick | < graphicsmagick 1.1.7-13 (bookworm) | graphicsmagick 1.1.7-13 (bookworm) |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.7-13 | 1.1.7-13 |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.7-13 | 1.1.7-13 |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.7-13 | 1.1.7-13 |
| graphicsmagick | graphicsmagick | >= 0 < 1.1.7-13 | 1.1.7-13 |
| imagemagick | graphicsmagick | — | — |
| imagemagick | graphicsmagick | — | — |
| imagemagick | graphicsmagick | — | — |
| imagemagick | graphicsmagick | — | — |
| imagemagick | graphicsmagick | — | — |
| imagemagick | graphicsmagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | >= 0 < 7:6.2.4.5.dfsg1-1 | 7:6.2.4.5.dfsg1-1 |
| imagemagick | imagemagick | >= 0 < 7:6.2.4.5.dfsg1-1 | 7:6.2.4.5.dfsg1-1 |
| imagemagick | imagemagick | >= 0 < 7:6.2.4.5.dfsg1-1 | 7:6.2.4.5.dfsg1-1 |
| imagemagick | imagemagick | >= 0 < 7:6.2.4.5.dfsg1-1 | 7:6.2.4.5.dfsg1-1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2008-1097: graphicsmagick - Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in code...
vendor_debian·2008·CVSS 6.8
CVE-2008-1097 [MEDIUM] CVE-2008-1097: graphicsmagick - Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in code...
Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx.c in (1) ImageMagick 6.2.4-5 and 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .pcx file that triggers incorrect memory allocation for the scanline array, leading to memory corruption.
Scope: local
bookworm: resolved (fixed in 1.1.7-13)
bullseye: resolved (fixed in 1.1.7-13)
forky: resolved (fixed in 1.1.7-13)
sid: resolved (fixed in 1.1.7-13)
trixie: resolved (fixed in 1.1.7-13)
Red Hat
Memory corruption in ImageMagick's PCX coder
vendor_redhat·2007-03-11·CVSS 6.8
CVE-2008-1097 [MEDIUM] Memory corruption in ImageMagick's PCX coder
Memory corruption in ImageMagick's PCX coder
Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx.c in (1) ImageMagick 6.2.4-5 and 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .pcx file that triggers incorrect memory allocation for the scanline array, leading to memory corruption.
GHSA
GHSA-w4vc-7rfv-99f6: Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx
ghsa_unreviewed·2022-05-01
CVE-2008-1097 [MEDIUM] GHSA-w4vc-7rfv-99f6: Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx
Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx.c in (1) ImageMagick 6.2.4-5 and 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .pcx file that triggers incorrect memory allocation for the scanline array, leading to memory corruption.
OSV
CVE-2008-1097: Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx
osv·2008-03-05·CVSS 6.8
CVE-2008-1097 [MEDIUM] CVE-2008-1097: Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx
Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx.c in (1) ImageMagick 6.2.4-5 and 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .pcx file that triggers incorrect memory allocation for the scanline array, leading to memory corruption.
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=413034http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.htmlhttp://osvdb.org/43213http://secunia.com/advisories/29786http://secunia.com/advisories/29857http://secunia.com/advisories/30967http://secunia.com/advisories/36260http://secunia.com/advisories/55721http://security.gentoo.org/glsa/glsa-201311-10.xmlhttp://www.debian.org/security/2009/dsa-1858http://www.mandriva.com/security/advisories?name=MDVSA-2008:099http://www.redhat.com/support/errata/RHSA-2008-0145.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0165.htmlhttp://www.securityfocus.com/bid/28822http://www.securitytracker.com/id?1019881https://bugzilla.redhat.com/show_bug.cgi?id=285861https://exchange.xforce.ibmcloud.com/vulnerabilities/41193https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11237http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=413034http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.htmlhttp://osvdb.org/43213http://secunia.com/advisories/29786http://secunia.com/advisories/29857http://secunia.com/advisories/30967http://secunia.com/advisories/36260http://secunia.com/advisories/55721http://security.gentoo.org/glsa/glsa-201311-10.xmlhttp://www.debian.org/security/2009/dsa-1858http://www.mandriva.com/security/advisories?name=MDVSA-2008:099http://www.redhat.com/support/errata/RHSA-2008-0145.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0165.htmlhttp://www.securityfocus.com/bid/28822http://www.securitytracker.com/id?1019881https://bugzilla.redhat.com/show_bug.cgi?id=285861https://exchange.xforce.ibmcloud.com/vulnerabilities/41193https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11237
2008-03-05
Published