Jump to content

Advisories MDKSA-2006:155: Updated ImageMagick packages fix vulnerabilities


paul
 Share

Recommended Posts

Multiple buffer overflows in ImageMagick before 6.2.9 allow user-assisted

attackers to execute arbitrary code via crafted XCF images. (CVE-2006-3743)

 

Multiple integer overflows in ImageMagick before 6.2.9 allows user-assisted

attackers to execute arbitrary code via crafted Sun bitmap images that trigger

heap-based buffer overflows. (CVE-2006-3744)

 

Integer overflow in the ReadSGIImage function in sgi.c in ImageMagick before

6.2.9 allows user-assisted attackers to cause a denial of service (crash)

and possibly execute arbitrary code via large (1) bytes_per_pixel, (2)

columns, and (3) rows values, which trigger a heap-based buffer overflow.

(CVE-2006-4144)

 

The updated packages have been patched to correct these issues.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...