|
ImageMagick XWD Decoding Denial of Service Vulnerability
|
|
|
|
|
Secunia Advisory:
|
SA15429
|
|
|
Release Date:
|
2005-05-23
|
|
Last Update:
|
2005-05-26
|
|
|
Critical:
|

Not critical
|
|
Impact:
|
DoS
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | ImageMagick 6.x
|
| | CVE reference: | CVE-2005-1739 (Secunia mirror)
|
|
|
Want to know the next time vulnerabilities are fixed in this product? - Companies can be alerted via email and SMS! |
|
|
Description: Tavis Ormandy has reported a weakness in ImageMagick, which can be exploited by malicious people to cause a DoS (Denial of Service).
The problem is caused due to an infinite loop in the XWD decoder when setting a colour mask and can be exploited to consume a large amount of CPU resources via a specially crafted image.
Do you have this product installed on your home computer? Scan using the free Personal Software Inspector. Check if a vulnerable version is installed on computers in your corporate network, scan using the Network Software Inspector.
Solution: Update to version 6.2.2-3.
Provided and/or discovered by: Tavis Ormandy, Gentoo Linux Security Audit Team.
Changelog: 2005-05-26: Added CVE reference.
Original Advisory: Gentoo:
http://www.gentoo.org/security/en/glsa/glsa-200505-16.xml
|
|
|
|
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
|
12 Related Secunia Security Advisories, displaying 10
|
|
|
1. ImageMagick Multiple Vulnerabilities
|
|
2. ImageMagick DCM and XWD Buffer Overflows
|
|
3. ImageMagick PALM and DCM Buffer Overflows
|
|
4. ImageMagick XCF and Sun Rasterfile Buffer Overflows
|
|
5. ImageMagick "ReadSGIImage()" Integer Overflow Vulnerability
|
|
6. ImageMagick Utilities Image Filename Handling Two Vulnerabilities
|
|
7. ImageMagick PNM Image Decoding Buffer Overflow Vulnerability
|
|
8. Imagemagick Filename Handling Format String Vulnerability
|
|
9. ImageMagick PSD Image Decoding Buffer Overflow
|
|
10. ImageMagick EXIF Parser Buffer Overflow Vulnerability
|
Show all related advisories
|
|
|
Send Feedback to Secunia
|
|
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.
|
|
|
|