Vulnerability Name: | CVE-2006-4144 (CCN-28372) | ||||||||||||||||||||
Assigned: | 2006-08-14 | ||||||||||||||||||||
Published: | 2006-08-14 | ||||||||||||||||||||
Updated: | 2018-10-17 | ||||||||||||||||||||
Summary: | Integer overflow in the ReadSGIImage function in sgi.c in ImageMagick before 6.2.9 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via large (1) bytes_per_pixel, (2) columns, and (3) rows values, which trigger a heap-based buffer overflow. | ||||||||||||||||||||
CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||
CVSS v2 Severity: | 2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P) 2.0 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C)
4.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C)
| ||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||
References: | Source: SGI Type: UNKNOWN 20060901-01-P Source: CCN Type: Full-Disclosure Mailing List, Mon Aug 14 2006 - 12:45:16 CDT [Overflow.pl] ImageMagick ReadSGIImage() Heap Overflow Source: MITRE Type: CNA CVE-2006-4144 Source: CCN Type: RHSA-2006-0633 ImageMagick security update Source: CCN Type: SA21462 ImageMagick "ReadSGIImage()" Integer Overflow Vulnerability Source: SECUNIA Type: Patch, Vendor Advisory 21462 Source: SECUNIA Type: UNKNOWN 21525 Source: SECUNIA Type: UNKNOWN 21621 Source: SECUNIA Type: UNKNOWN 21671 Source: SECUNIA Type: UNKNOWN 21679 Source: SECUNIA Type: UNKNOWN 21832 Source: SECUNIA Type: UNKNOWN 22036 Source: SECUNIA Type: UNKNOWN 22096 Source: SECUNIA Type: UNKNOWN 22998 Source: GENTOO Type: UNKNOWN GLSA-200609-14 Source: SREASON Type: UNKNOWN 1385 Source: CCN Type: SECTRACK ID: 1016699 ImageMagick ReadSGIImage() Heap Overflow Lets Remote Users Execute Arbitrary Code Source: SECTRACK Type: UNKNOWN 1016699 Source: CCN Type: ASA-2006-206 ImageMagick security update (RHSA-2006-0633) Source: DEBIAN Type: UNKNOWN DSA-1213 Source: DEBIAN Type: DSA-1213 imagemagick -- several vulnerabilities Source: CCN Type: GLSA-200609-14 ImageMagick: Multiple Vulnerabilities Source: CCN Type: ImageMagick Web site Introduction to ImageMagick Source: MANDRIVA Type: UNKNOWN MDKSA-2006:155 Source: SUSE Type: UNKNOWN SUSE-SA:2006:050 Source: MISC Type: Exploit http://www.overflow.pl/adv/imsgiheap.txt Source: REDHAT Type: UNKNOWN RHSA-2006:0633 Source: BUGTRAQ Type: UNKNOWN 20060814 [Overflow.pl] ImageMagick ReadSGIImage() Heap Overflow Source: BUGTRAQ Type: UNKNOWN 20060816 Re: [Overflow.pl] ImageMagick ReadSGIImage() Heap Overflow Source: BID Type: Exploit 19507 Source: CCN Type: BID-19507 ImageMagick SGI Image File Remote Heap Buffer Overflow Vulnerability Source: CCN Type: TLSA-2007-5 Multiple buffer overflow Source: CCN Type: USN-337-1 imagemagick vulnerability Source: UBUNTU Type: UNKNOWN USN-337-1 Source: XF Type: UNKNOWN imagemagick-readsgiimage-bo(28372) Source: XF Type: UNKNOWN imagemagick-readsgiimage-bo(28372) Source: CONFIRM Type: UNKNOWN https://issues.rpath.com/browse/RPL-605 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:11129 Source: SUSE Type: SUSE-SA:2006:050 ImageMagick security problems | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Denotes that component is vulnerable | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |