CVE-2009-1882
published 2009-06-02CVE-2009-1882: Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial of…
PriorityP341critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
7.15%
93.6th percentile
Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF file, which triggers a buffer overflow. NOTE: some of these details are obtained from third party information.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | graphicsmagick | < graphicsmagick 1.3.5-5.1 (bookworm) | graphicsmagick 1.3.5-5.1 (bookworm) |
| debian | imagemagick | < graphicsmagick 1.3.5-5.1 (bookworm) | graphicsmagick 1.3.5-5.1 (bookworm) |
| graphicsmagick | graphicsmagick | >= 0 < 1.3.5-5.1 | 1.3.5-5.1 |
| graphicsmagick | graphicsmagick | >= 0 < 1.3.5-5.1 | 1.3.5-5.1 |
| graphicsmagick | graphicsmagick | >= 0 < 1.3.5-5.1 | 1.3.5-5.1 |
| graphicsmagick | graphicsmagick | >= 0 < 1.3.5-5.1 | 1.3.5-5.1 |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | >= 0 < 7:6.5.1.0-1.1 | 7:6.5.1.0-1.1 |
| imagemagick | imagemagick | >= 0 < 7:6.5.1.0-1.1 | 7:6.5.1.0-1.1 |
| imagemagick | imagemagick | >= 0 < 7:6.5.1.0-1.1 | 7:6.5.1.0-1.1 |
| imagemagick | imagemagick | >= 0 < 7:6.5.1.0-1.1 | 7:6.5.1.0-1.1 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3MEDIUM
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cw2f-4p3w-w2xh: Integer overflow in the XMakeImage function in magick/xwindow
ghsa_unreviewed·2022-05-02
CVE-2009-1882 [HIGH] GHSA-cw2f-4p3w-w2xh: Integer overflow in the XMakeImage function in magick/xwindow
Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF file, which triggers a buffer overflow. NOTE: some of these details are obtained from third party information.
OSV
CVE-2009-1882: Integer overflow in the XMakeImage function in magick/xwindow
osv·2009-06-02·CVSS 9.3
CVE-2009-1882 [CRITICAL] CVE-2009-1882: Integer overflow in the XMakeImage function in magick/xwindow
Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF file, which triggers a buffer overflow. NOTE: some of these details are obtained from third party information.
Ubuntu
ImageMagick vulnerability
vendor_ubuntu·2009-06-08
CVE-2009-1882 ImageMagick vulnerability
Title: ImageMagick vulnerability
Summary: ImageMagick vulnerability
It was discovered that ImageMagick did not properly verify the dimensions
of TIFF files. If a user or automated system were tricked into opening a
crafted TIFF file, an attacker could cause a denial of service or possibly
execute arbitrary code with the privileges of the user invoking the
program.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
GraphicsMagick: Integer overflow in the routine creating X11 images
vendor_redhat·2009-05-27·CVSS 9.3
CVE-2009-1882 [CRITICAL] CWE-190 GraphicsMagick: Integer overflow in the routine creating X11 images
GraphicsMagick: Integer overflow in the routine creating X11 images
Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF file, which triggers a buffer overflow. NOTE: some of these details are obtained from third party information.
Debian
CVE-2009-1882: graphicsmagick - Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6...
vendor_debian·2009·CVSS 9.3
CVE-2009-1882 [CRITICAL] CVE-2009-1882: graphicsmagick - Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6...
Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF file, which triggers a buffer overflow. NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: resolved (fixed in 1.3.5-5.1)
bullseye: resolved (fixed in 1.3.5-5.1)
forky: resolved (fixed in 1.3.5-5.1)
sid: resolved (fixed in 1.3.5-5.1)
trixie: resolved (fixed in 1.3.5-5.1)
No detection rules found.
No public exploits indexed.
http://imagemagick.org/script/changelog.phphttp://lists.fedoraproject.org/pipermail/package-announce/2010-January/033766.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-January/033833.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.htmlhttp://mirror1.smudge-it.co.uk/imagemagick/www/changelog.htmlhttp://osvdb.org/54729http://secunia.com/advisories/35216http://secunia.com/advisories/35382http://secunia.com/advisories/35685http://secunia.com/advisories/36260http://secunia.com/advisories/37959http://secunia.com/advisories/55721http://security.gentoo.org/glsa/glsa-201311-10.xmlhttp://wiki.rpath.com/Advisories:rPSA-2010-0074http://www.debian.org/security/2009/dsa-1858http://www.openwall.com/lists/oss-security/2009/06/08/1http://www.securityfocus.com/archive/1/514516/100/0/threadedhttp://www.securityfocus.com/bid/35111http://www.vupen.com/english/advisories/2009/1449https://usn.ubuntu.com/784-1/http://imagemagick.org/script/changelog.phphttp://lists.fedoraproject.org/pipermail/package-announce/2010-January/033766.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-January/033833.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.htmlhttp://mirror1.smudge-it.co.uk/imagemagick/www/changelog.htmlhttp://osvdb.org/54729http://secunia.com/advisories/35216http://secunia.com/advisories/35382http://secunia.com/advisories/35685http://secunia.com/advisories/36260http://secunia.com/advisories/37959http://secunia.com/advisories/55721http://security.gentoo.org/glsa/glsa-201311-10.xmlhttp://wiki.rpath.com/Advisories:rPSA-2010-0074http://www.debian.org/security/2009/dsa-1858http://www.openwall.com/lists/oss-security/2009/06/08/1http://www.securityfocus.com/archive/1/514516/100/0/threadedhttp://www.securityfocus.com/bid/35111http://www.vupen.com/english/advisories/2009/1449https://usn.ubuntu.com/784-1/
2009-06-02
Published