ImageMagick.SGI.Image.File.Buffer.Overflow

description-logoDescription

This indicates an attack attempt against a heap-based buffer-overflow vulnerability in ImageMagick due to improper bounds checking in the ReadSGIImage() function.
The vulnerability may lead to a denial-of-service attack or possibly execution of remote code via a crafted SGI file.

affected-products-logoAffected Products

Ubuntu Ubuntu Linux 5.10 sparc
Ubuntu Ubuntu Linux 5.10 powerpc
Ubuntu Ubuntu Linux 5.10 i386
Ubuntu Ubuntu Linux 5.10 amd64
Ubuntu Ubuntu Linux 5.0 4 powerpc
Ubuntu Ubuntu Linux 5.0 4 i386
Ubuntu Ubuntu Linux 5.0 4 amd64
Ubuntu Ubuntu Linux 6.06 LTS sparc
Ubuntu Ubuntu Linux 6.06 LTS powerpc
Ubuntu Ubuntu Linux 6.06 LTS i386
Ubuntu Ubuntu Linux 6.06 LTS amd64
Trustix Secure Linux 3.0
Trustix Secure Linux 2.2
S.u.S.E. SuSE Linux Standard Server 8.0
S.u.S.E. SuSE Linux School Server for i386
S.u.S.E. SUSE Linux Enterprise Desktop 10
S.u.S.E. Linux Professional 10.0 OSS
S.u.S.E. Linux Professional 10.0
S.u.S.E. Linux Professional 9.3 x86_64
S.u.S.E. Linux Professional 9.3
S.u.S.E. Linux Professional 9.2 x86_64
S.u.S.E. Linux Professional 9.2
S.u.S.E. Linux Professional 10.1
S.u.S.E. Linux Personal 10.0 OSS
S.u.S.E. Linux Personal 9.3 x86_64
S.u.S.E. Linux Personal 9.3
S.u.S.E. Linux Personal 9.2 x86_64
S.u.S.E. Linux Personal 9.2
S.u.S.E. Linux Personal 10.1
S.u.S.E. Linux Openexchange Server
S.u.S.E. Linux Enterprise Server SDK 9
S.u.S.E. Linux Enterprise SDK 10
S.u.S.E. Linux Desktop 1.0
rPath rPath Linux 1
RedHat Fedora Core5
RedHat Enterprise Linux WS 4
RedHat Enterprise Linux WS 3
RedHat Enterprise Linux WS 2.1 IA64
RedHat Enterprise Linux WS 2.1
RedHat Enterprise Linux ES 4
RedHat Enterprise Linux ES 3
RedHat Enterprise Linux ES 2.1 IA64
RedHat Enterprise Linux ES 2.1
RedHat Enterprise Linux AS 4
RedHat Enterprise Linux AS 3
RedHat Enterprise Linux AS 2.1 IA64
RedHat Enterprise Linux AS 2.1
RedHat Desktop 4.0
RedHat Desktop 3.0
RedHat Advanced Workstation for the Itanium Processor 2.1
Novell Linux Desktop 9
MandrakeSoft Linux Mandrake 2006.0 x86_64
MandrakeSoft Linux Mandrake 2006.0
MandrakeSoft Corporate Server 3.0 x86_64
MandrakeSoft Corporate Server 3.0
ImageMagick ImageMagick 6.2.8
ImageMagick ImageMagick 6.2.7
ImageMagick ImageMagick 6.2.6
ImageMagick ImageMagick 6.2.5
ImageMagick ImageMagick 6.2.4 .5
ImageMagick ImageMagick 6.2.4
ImageMagick ImageMagick 6.2.2
ImageMagick ImageMagick 6.2.1
ImageMagick ImageMagick 6.2 .0.7
ImageMagick ImageMagick 6.2 .0.4
ImageMagick ImageMagick 6.2
ImageMagick ImageMagick 6.1.8
ImageMagick ImageMagick 6.1.7
ImageMagick ImageMagick 6.1.6
ImageMagick ImageMagick 6.1.5
ImageMagick ImageMagick 6.1.4
ImageMagick ImageMagick 6.1.3
ImageMagick ImageMagick 6.1.2
ImageMagick ImageMagick 6.1.1
ImageMagick ImageMagick 6.1
ImageMagick ImageMagick 6.0.8
ImageMagick ImageMagick 6.0.7
ImageMagick ImageMagick 6.0.6
ImageMagick ImageMagick 6.0.5
ImageMagick ImageMagick 6.0.4
ImageMagick ImageMagick 6.0.3
ImageMagick ImageMagick 6.0.2 .5
ImageMagick ImageMagick 6.0.2
ImageMagick ImageMagick 6.0.1
ImageMagick ImageMagick 6.0
Gentoo Linux

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.
Denial of Service: Remote attackers can crash vulnerable systems.

recomended-action-logoRecommended Actions

Upgrade to the latest version of ImageMagick (version 6.2.9 or later):
http://www.imagemagick.org/script/index.php

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)