ImageMagick Display Filename Format String Vulnerability
BID:8177
Info
ImageMagick Display Filename Format String Vulnerability
| Bugtraq ID: | 8177 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jul 14 2003 12:00AM |
| Updated: | Jul 14 2003 12:00AM |
| Credit: | Discovery of this issue is credited to Angelo Rosiello <[email protected]>. |
| Vulnerable: |
ImageMagick ImageMagick 5.4.3 |
| Not Vulnerable: | |
Discussion
ImageMagick Display Filename Format String Vulnerability
The ImageMagick display program is alleged to be prone to a format string vulnerability. Exploitation may occur when the program is invoked with a filename that includes malicious format specifiers, potentially resulting in execution of arbitrary code in the context of the user running the program.
This issue was reported for Unix/Linux platforms. It is not known if other platforms are similarly affected.
The ImageMagick display program is alleged to be prone to a format string vulnerability. Exploitation may occur when the program is invoked with a filename that includes malicious format specifiers, potentially resulting in execution of arbitrary code in the context of the user running the program.
This issue was reported for Unix/Linux platforms. It is not known if other platforms are similarly affected.
Solution / Fix
ImageMagick Display Filename Format String Vulnerability
Solution:
The vendor has been reported to have addressed this issue. This has not been confirmed by Symantec. Users are advised to contact the vendor about the availability of fixes.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The vendor has been reported to have addressed this issue. This has not been confirmed by Symantec. Users are advised to contact the vendor about the availability of fixes.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.