ImageMagick PNM Image Decoding Remote Buffer Overflow Vulnerability

BID:13351

Info

ImageMagick PNM Image Decoding Remote Buffer Overflow Vulnerability

Bugtraq ID: 13351
Class: Boundary Condition Error
CVE: CVE-2005-1275
Remote: Yes
Local: No
Published: Apr 25 2005 12:00AM
Updated: Mar 08 2007 03:15AM
Credit: Damian Put <[email protected]> is credited with the discovery of this issue.
Vulnerable: Turbolinux Turbolinux Workstation 8.0
Turbolinux Turbolinux Workstation 7.0
Turbolinux Turbolinux Server 8.0
Turbolinux Turbolinux Server 7.0
Turbolinux Turbolinux Desktop 10.0
Turbolinux Turbolinux 10 F...
Turbolinux Home
Trustix Secure Linux 2.2
Trustix Secure Linux 2.1
Trustix Secure Enterprise Linux 2.0
SGI ProPack 3.0
SGI Advanced Linux Environment 3.0
Redhat Linux 9.0 i386
Redhat Linux 7.3 i686
Redhat Linux 7.3 i386
Redhat Linux 7.3
Redhat Fedora Core3
Redhat Fedora Core2
Redhat Fedora Core1
Redhat Enterprise Linux WS 3
Redhat Enterprise Linux ES 3
Redhat Enterprise Linux AS 3
Redhat Desktop 3.0
Mandriva Linux Mandrake 10.2 x86_64
Mandriva Linux Mandrake 10.2
MandrakeSoft Corporate Server 3.0 x86_64
MandrakeSoft Corporate Server 3.0
MandrakeSoft Corporate Server 2.1 x86_64
MandrakeSoft Corporate Server 2.1
ImageMagick ImageMagick 6.2.1
ImageMagick ImageMagick 6.2 .0.7
+ Redhat Fedora Core3
+ Redhat Fedora Core2
ImageMagick ImageMagick 6.2 .0.4
+ Gentoo Linux
ImageMagick ImageMagick 6.2
ImageMagick ImageMagick 6.1.8
+ Gentoo Linux
ImageMagick ImageMagick 6.1.7
ImageMagick ImageMagick 6.1.6
ImageMagick ImageMagick 6.1.5
ImageMagick ImageMagick 6.1.4
ImageMagick ImageMagick 6.1.3
ImageMagick ImageMagick 6.1.2
ImageMagick ImageMagick 6.1.1
ImageMagick ImageMagick 6.1
ImageMagick ImageMagick 6.0.8
ImageMagick ImageMagick 6.0.7
+ Redhat Desktop 4.0
+ Redhat Enterprise Linux Desktop version 4
+ Redhat Enterprise Linux AS 4
+ Redhat Enterprise Linux ES 4
+ Redhat Enterprise Linux WS 4
+ S.u.S.E. Linux Personal 9.2 x86_64
+ S.u.S.E. Linux Personal 9.2
ImageMagick ImageMagick 6.0.6
+ Ubuntu Ubuntu Linux 5.0 4 powerpc
+ Ubuntu Ubuntu Linux 5.0 4 i386
+ Ubuntu Ubuntu Linux 5.0 4 amd64
ImageMagick ImageMagick 6.0.5
+ Turbolinux Home
+ Turbolinux Turbolinux Desktop 10.0
+ Turbolinux Turbolinux Server 10.0
ImageMagick ImageMagick 6.0.4
+ Mandriva Linux Mandrake 10.1 x86_64
+ Mandriva Linux Mandrake 10.1
ImageMagick ImageMagick 6.0.3
ImageMagick ImageMagick 6.0.2 .5
+ Ubuntu Ubuntu Linux 4.1 ppc
+ Ubuntu Ubuntu Linux 4.1 ia64
+ Ubuntu Ubuntu Linux 4.1 ia32
ImageMagick ImageMagick 6.0.2
+ Ubuntu Ubuntu Linux 4.1 ppc
+ Ubuntu Ubuntu Linux 4.1 ia64
+ Ubuntu Ubuntu Linux 4.1 ia32
ImageMagick ImageMagick 6.0.1
ImageMagick ImageMagick 6.0
ImageMagick ImageMagick 6.2.9.2
ImageMagick ImageMagick 6.2.0.3
ImageMagick ImageMagick 6.0.4.4
+ Mandriva Linux Mandrake 10.1 x86_64
+ Mandriva Linux Mandrake 10.1
ImageMagick ImageMagick 5.5.7.15
+ Mandriva Linux Mandrake 10.0 AMD64
+ Mandriva Linux Mandrake 10.0
+ Mandriva Linux Mandrake 9.2 amd64
+ Mandriva Linux Mandrake 9.2
+ S.u.S.E. Linux Personal 9.1 x86_64
+ S.u.S.E. Linux Personal 9.1
+ S.u.S.E. Linux Personal 9.0 x86_64
+ S.u.S.E. Linux Personal 9.0
ImageMagick ImageMagick 5.4.2.3
+ Turbolinux Turbolinux Workstation 8.0
GraphicsMagick GraphicsMagick 1.1.5
GraphicsMagick GraphicsMagick 1.1.5
+ Gentoo Linux
GraphicsMagick GraphicsMagick 1.1.4
GraphicsMagick GraphicsMagick 1.1.3
GraphicsMagick GraphicsMagick 1.1
GraphicsMagick GraphicsMagick 1.0.6
GraphicsMagick GraphicsMagick 1.0
Not Vulnerable: ImageMagick ImageMagick 6.2.2
+ Gentoo Linux
GraphicsMagick GraphicsMagick 1.1.6
+ Gentoo Linux

Discussion

ImageMagick PNM Image Decoding Remote Buffer Overflow Vulnerability

A remotely exploitable client-side buffer-overflow vulnerability affects ImageMagick. This issue occurs because the application fails to properly validate the length of user-supplied strings before copying them into static process buffers.

An attacker may exploit this issue to cause the affected application to crash, potentially destroying unsaved data, ultimately denying service to legitimate users.

Exploit / POC

ImageMagick PNM Image Decoding Remote Buffer Overflow Vulnerability

The following command will craft a malicious file designed to leverage this issue:

perl -e 'print "P7\n1\n1 1\n1"' > vuln.pnm

Solution / Fix

ImageMagick PNM Image Decoding Remote Buffer Overflow Vulnerability

Solution:
The vendor has released an upgrade dealing with this issue. Please see the referenced advisories for more information.


ImageMagick ImageMagick 5.5.7.15

Redhat Fedora Core2

Redhat Fedora Core1

ImageMagick ImageMagick 6.2.0.3

ImageMagick ImageMagick 6.0.4.4

GraphicsMagick GraphicsMagick 1.0

GraphicsMagick GraphicsMagick 1.0.6

GraphicsMagick GraphicsMagick 1.1

GraphicsMagick GraphicsMagick 1.1.3

GraphicsMagick GraphicsMagick 1.1.4

GraphicsMagick GraphicsMagick 1.1.5

GraphicsMagick GraphicsMagick 1.1.5

ImageMagick ImageMagick 6.0

ImageMagick ImageMagick 6.0.1

ImageMagick ImageMagick 6.0.2

ImageMagick ImageMagick 6.0.2 .5

ImageMagick ImageMagick 6.0.3

ImageMagick ImageMagick 6.0.4

ImageMagick ImageMagick 6.0.5

ImageMagick ImageMagick 6.0.6

ImageMagick ImageMagick 6.0.7

ImageMagick ImageMagick 6.0.8

ImageMagick ImageMagick 6.1

ImageMagick ImageMagick 6.1.1

ImageMagick ImageMagick 6.1.2

ImageMagick ImageMagick 6.1.3

ImageMagick ImageMagick 6.1.4

ImageMagick ImageMagick 6.1.5

ImageMagick ImageMagick 6.1.6

ImageMagick ImageMagick 6.1.7

ImageMagick ImageMagick 6.1.8

ImageMagick ImageMagick 6.2 .0.4

ImageMagick ImageMagick 6.2 .0.7

ImageMagick ImageMagick 6.2

ImageMagick ImageMagick 6.2.1

Redhat Linux 7.3 i386

Redhat Linux 7.3 i686

Redhat Linux 7.3

Redhat Linux 9.0 i386

References

ImageMagick PNM Image Decoding Remote Buffer Overflow Vulnerability

References:
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report