[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-1097Date: (C)2008-03-05   (M)2024-02-09


Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx.c in (1) ImageMagick 6.2.4-5 and 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .pcx file that triggers incorrect memory allocation for the scanline array, leading to memory corruption.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.8
Exploit Score: 8.6
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1019881
BID-28822
SECUNIA-29786
SECUNIA-29857
SECUNIA-30967
SECUNIA-36260
OSVDB-43213
SECUNIA-55721
DSA-1858
GLSA-201311-10
MDVSA-2008:099
RHSA-2008:0145
RHSA-2008:0165
SUSE-SR:2008:014
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=413034
https://bugzilla.redhat.com/show_bug.cgi?id=285861
imagemagick-readpcximage-bo(41193)
oval:org.mitre.oval:def:11237

CPE    4
cpe:/a:imagemagick:imagemagick:6.2.8.2
cpe:/a:imagemagick:imagemagick:6.2.8.3
cpe:/a:imagemagick:imagemagick:6.2.8.0
cpe:/a:imagemagick:imagemagick:6.2.8.1
...
CWE    1
CWE-399
OVAL    3
oval:org.secpod.oval:def:301309
oval:org.secpod.oval:def:600468
oval:org.mitre.oval:def:8206

© SecPod Technologies