ImageMagick SGI Image File Unspecified Remote Heap Buffer Overflow Vulnerability
BID:21185
Info
ImageMagick SGI Image File Unspecified Remote Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 21185 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-5868 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 20 2006 12:00AM |
| Updated: | Feb 23 2007 04:46PM |
| Credit: | Daniel Kobras discovered this vulnerability. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.10 sparc Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Server 10.0.0 x64 Turbolinux Turbolinux Desktop 10.0 Turbolinux Turbolinux FUJI Turbolinux Turbolinux 10 F... TurboLinux Personal Turbolinux Home Turbolinux Appliance Server 2.0 TransSoft Broker FTP Server 8.0 SGI ProPack 3.0 SP6 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 ImageMagick ImageMagick 6.2.8 ImageMagick ImageMagick 6.2.7 ImageMagick ImageMagick 6.2.6 ImageMagick ImageMagick 6.2.5 ImageMagick ImageMagick 6.2.4 .5 ImageMagick ImageMagick 6.2.4 ImageMagick ImageMagick 6.2.3 ImageMagick ImageMagick 6.2.2 ImageMagick ImageMagick 6.2.1 ImageMagick ImageMagick 6.2 .0.7 ImageMagick ImageMagick 6.2 .0.4 ImageMagick ImageMagick 6.2 ImageMagick ImageMagick 6.1.8 ImageMagick ImageMagick 6.1.7 ImageMagick ImageMagick 6.1.6 ImageMagick ImageMagick 6.1.5 ImageMagick ImageMagick 6.1.4 ImageMagick ImageMagick 6.1.3 ImageMagick ImageMagick 6.1.2 ImageMagick ImageMagick 6.1.1 ImageMagick ImageMagick 6.1 ImageMagick ImageMagick 6.0.8 ImageMagick ImageMagick 6.0.7 ImageMagick ImageMagick 6.0.6 ImageMagick ImageMagick 6.0.5 ImageMagick ImageMagick 6.0.4 ImageMagick ImageMagick 6.0.3 ImageMagick ImageMagick 6.0.2 .5 ImageMagick ImageMagick 6.0.2 ImageMagick ImageMagick 6.0.1 ImageMagick ImageMagick 6.0 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
ImageMagick ImageMagick 6.2.9 |
Discussion
ImageMagick SGI Image File Unspecified Remote Heap Buffer Overflow Vulnerability
ImageMagick is prone to a remote heap-based buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Exploiting this issue allows attackers to execute arbitrary machine code in the context of applications that use the ImageMagick library.
ImageMagick versions in the 6.x series, up to version 6.2.8, are vulnerable to this issue.
ImageMagick is prone to a remote heap-based buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Exploiting this issue allows attackers to execute arbitrary machine code in the context of applications that use the ImageMagick library.
ImageMagick versions in the 6.x series, up to version 6.2.8, are vulnerable to this issue.
Exploit / POC
ImageMagick SGI Image File Unspecified Remote Heap Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
The following proof-of-concept image file demonstrates this issue to trigger application crashes.
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
The following proof-of-concept image file demonstrates this issue to trigger application crashes.
Solution / Fix
ImageMagick SGI Image File Unspecified Remote Heap Buffer Overflow Vulnerability
Solution:
Please see the references for more information and fixes.
ImageMagick ImageMagick 6.2.4 .5
Solution:
Please see the references for more information and fixes.
ImageMagick ImageMagick 6.2.4 .5
-
Ubuntu imagemagick_6.2.4.5-0.6ubuntu0.4_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/i/imagemagick/imagemagick_ 6.2.4.5-0.6ubuntu0.4_amd64.deb -
Ubuntu imagemagick_6.2.4.5-0.6ubuntu0.4_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/i/imagemagick/imagemagick_ 6.2.4.5-0.6ubuntu0.4_i386.deb -
Ubuntu imagemagick_6.2.4.5-0.6ubuntu0.4_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/i/imagemagick/imagemagick_ 6.2.4.5-0.6ubuntu0.4_powerpc.deb -
Ubuntu imagemagick_6.2.4.5-0.6ubuntu0.4_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/i/imagemagick/imagemagick_ 6.2.4.5-0.6ubuntu0.4_sparc.deb -
Ubuntu libmagick++9-dev_6.2.4.5-0.6ubuntu0.4_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/i/imagemagick/libmagick++9 -dev_6.2.4.5-0.6ubuntu0.4_amd64.deb -
Ubuntu libmagick++9-dev_6.2.4.5-0.6ubuntu0.4_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/i/imagemagick/libmagick++9 -dev_6.2.4.5-0.6ubuntu0.4_i386.deb -
Ubuntu libmagick++9-dev_6.2.4.5-0.6ubuntu0.4_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/i/imagemagick/libmagick++9 -dev_6.2.4.5-0.6ubuntu0.4_powerpc.deb -
Ubuntu libmagick++9-dev_6.2.4.5-0.6ubuntu0.4_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/i/imagemagick/libmagick++9 -dev_6.2.4.5-0.6ubuntu0.4_sparc.deb -
Ubuntu libmagick++9c2a_6.2.4.5-0.6ubuntu0.4_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/i/imagemagick/libmagick++9 c2a_6.2.4.5-0.6ubuntu0.4_amd64.deb -
Ubuntu libmagick++9c2a_6.2.4.5-0.6ubuntu0.4_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/i/imagemagick/libmagick++9 c2a_6.2.4.5-0.6ubuntu0.4_i386.deb -
Ubuntu libmagick++9c2a_6.2.4.5-0.6ubuntu0.4_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/i/imagemagick/libmagick++9 c2a_6.2.4.5-0.6ubuntu0.4_powerpc.deb -
Ubuntu libmagick++9c2a_6.2.4.5-0.6ubuntu0.4_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/i/imagemagick/libmagick++9 c2a_6.2.4.5-0.6ubuntu0.4_sparc.deb -
Ubuntu libmagick9-dev_6.2.4.5-0.6ubuntu0.4_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/i/imagemagick/libmagick9-d ev_6.2.4.5-0.6ubuntu0.4_amd64.deb -
Ubuntu libmagick9-dev_6.2.4.5-0.6ubuntu0.4_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/i/imagemagick/libmagick9-d ev_6.2.4.5-0.6ubuntu0.4_i386.deb -
Ubuntu libmagick9-dev_6.2.4.5-0.6ubuntu0.4_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/i/imagemagick/libmagick9-d ev_6.2.4.5-0.6ubuntu0.4_powerpc.deb -
Ubuntu libmagick9-dev_6.2.4.5-0.6ubuntu0.4_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/i/imagemagick/libmagick9-d ev_6.2.4.5-0.6ubuntu0.4_sparc.deb -
Ubuntu libmagick9_6.2.4.5-0.6ubuntu0.4_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/i/imagemagick/libmagick9_6 .2.4.5-0.6ubuntu0.4_amd64.deb -
Ubuntu libmagick9_6.2.4.5-0.6ubuntu0.4_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/i/imagemagick/libmagick9_6 .2.4.5-0.6ubuntu0.4_i386.deb -
Ubuntu libmagick9_6.2.4.5-0.6ubuntu0.4_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/i/imagemagick/libmagick9_6 .2.4.5-0.6ubuntu0.4_powerpc.deb -
Ubuntu libmagick9_6.2.4.5-0.6ubuntu0.4_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/i/imagemagick/libmagick9_6 .2.4.5-0.6ubuntu0.4_sparc.deb -
Ubuntu perlmagick_6.2.4.5-0.6ubuntu0.4_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/i/imagemagick/perlmagi ck_6.2.4.5-0.6ubuntu0.4_amd64.deb -
Ubuntu perlmagick_6.2.4.5-0.6ubuntu0.4_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/i/imagemagick/perlmagi ck_6.2.4.5-0.6ubuntu0.4_i386.deb -
Ubuntu perlmagick_6.2.4.5-0.6ubuntu0.4_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/i/imagemagick/perlmagi ck_6.2.4.5-0.6ubuntu0.4_powerpc.deb -
Ubuntu perlmagick_6.2.4.5-0.6ubuntu0.4_sparc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/universe/i/imagemagick/perlmagi ck_6.2.4.5-0.6ubuntu0.4_sparc.deb
References
ImageMagick SGI Image File Unspecified Remote Heap Buffer Overflow Vulnerability
References:
References:
- ImageMagick Homepage (ImageMagick)
- RHSA-2007:0015-5: ImageMagick security update (Red Hat)