Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

FLEA-2007-0006-2: ImageMagick
From: Foresight Linux Essential Announcement Service <foresight-security-noreply () foresightlinux org>
Date: Tue, 03 Apr 2007 14:18:52 -0400

Foresight Linux Essential Advisory: 2007-0006-2
Published: 2007-04-03
Updated:
    2007-04-03 Fix typo in updated group-dist version

Rating: Minor

Updated Versions:
    ImageMagick=/foresight.rpath.org () fl:1-devel//1/6.3.3.5-1-1
    group-dist=/foresight.rpath.org () fl:1-devel//1/1.1-0.11-5

References:
    https://issues.foresightlinux.org/browse/FL-222

http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=496
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1719

Description:
    Previous versions of the ImageMagick package were vulnerable to
buffer overflows in the code which parses DCM and XWD files, which could
allow an attacker to execute arbitrary code at the permission level of
the user running ImageMagick (usually non-root). The attacker would have
to convince a user to open the file in ImageMagick. While these file
formats are not common, it is possible to disguise the file such that it
appears to be a file of another, more common, type.



  By Date           By Thread  

Current thread:
  • FLEA-2007-0006-2: ImageMagick Foresight Linux Essential Announcement Service (Apr 03)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]