The load_tile function in the XCF coder in coders/xcf.c in (1) ImageMagick 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .xcf file that triggers an out-of-bounds heap write, possibly related to the ScaleCharToQuantum function.
Novell Linux Desktop 9 for x86 Novell Linux Desktop 9 for x86_64 Novell Linux Desktop 9 SDK for x86 Novell Linux Desktop 9 SDK for x86_64 openSUSE 10.3 openSUSE Tumbleweed SLES SDK 9 for IBM iSeries and IBM pSeries SLES SDK 9 for IBM S/390 and IBM zSeries SLES SDK 9 for IBM zSeries SLES SDK 9 for IPF SLES SDK 9 for x86 SLES SDK 9 for X86-64 SUSE LINUX 10.1 SUSE Linux Enterprise SDK 10 SP2 SUSE Linux Enterprise Software Development Kit 11 SP4