漏洞信息详情
ImageMagick sgi.c程序ReadSGIImage函数整型溢出漏洞
- CNNVD编号:CNNVD-200608-244
- 危害等级: 低危
- CVE编号:
CVE-2006-4144
- 漏洞类型:
缓冲区溢出
- 发布时间:
2006-08-15
- 威胁类型:
远程
- 更新时间:
2006-08-15
- 厂 商:
imagemagick - 漏洞来源:
Damian Put -
漏洞简介
ImageMagick before 6.2.9中sgi.c程序中的ReadSGIImage函数存在整型溢出,用户辅助攻击者可借助超大的:(1) bytes_per_pixel值,(2) 列值,和 (3) 行值, 引发堆缓冲区溢出,从而导致拒绝服务(崩溃)和执行任意代码。
漏洞公告
ImageMagick ImageMagick 6.0.7
-
SuSE ImageMagick-6.0.7-4.10.i586.rpmSUSE LINUX 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/ImageMagick-6.0.7 -
SuSE ImageMagick-6.0.7-4.10.x86_64.rpmSUSE LINUX 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/ImageMagick-6.0
-
SuSE ImageMagick-devel-6.0.7-4.10.i586.rpmSUSE LINUX 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/ImageMagick-devel
-
SuSE ImageMagick-devel-6.0.7-4.10.x86_64.rpmSUSE LINUX 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/ImageMagick-dev
-
SuSE ImageMagick-Magick++-6.0.7-4.10.i586.rpmSUSE LINUX 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/ImageMagick-Magic
-
SuSE ImageMagick-Magick++-6.0.7-4.10.x86_64.rpmSUSE LINUX 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/ImageMagick-Mag
-
SuSE ImageMagick-Magick++-devel-6.0.7-4.10.i586.rpmSUSE LINUX 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/ImageMagick-Magic
-
SuSE ImageMagick-Magick++-devel-6.0.7-4.10.x86_64.rpmSUSE LINUX 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/ImageMagick-Mag
-
SuSE perl-PerlMagick-6.0.7-4.10.i586.rpmSUSE LINUX 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/perl-PerlMagick-6
-
SuSE perl-PerlMagick-6.0.7-4.10.x86_64.rpmSUSE LINUX 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/perl-PerlMagick
ImageMagick ImageMagick 6.1.8
-
SuSE ImageMagick-6.1.8-6.4.i586.rpmSUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/ImageMagick-6.1.8
-
SuSE ImageMagick-6.1.8-6.4.x86_64.rpmSUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/ImageMagick-6.1
-
SuSE ImageMagick-devel-6.1.8-6.4.i586.rpmSUSE LINUX
参考网址
来源: SECUNIA
名称: 21462
链接:http://secunia.com/advisories/21462
来源: BID
名称: 19507
链接:http://www.securityfocus.com/bid/19507
来源: BUGTRAQ
名称: 20060814 [Overflow.pl] ImageMagick ReadSGIImage() Heap Overflow
链接:http://www.securityfocus.com/archive/1/archive/1/443208/100/0/threaded
来源: MISC
链接:http://www.overflow.pl/adv/imsgiheap.txt
来源: issues.rpath.com
链接:https://issues.rpath.com/browse/RPL-605
来源: XF
名称: imagemagick-readsgiimage-bo(28372)
链接:http://xforce.iss.net/xforce/xfdb/28372
来源: UBUNTU
名称: USN-337-1
链接:http://www.ubuntu.com/usn/usn-337-1
来源: BUGTRAQ
名称: 20060816 Re: [Overflow.pl] ImageMagick ReadSGIImage() Heap Overflow
链接:http://www.securityfocus.com/archive/1/archive/1/443362/100/0/threaded
来源: REDHAT
名称: RHSA-2006:0633
链接:http://www.redhat.com/support/errata/RHSA-2006-0633.html
来源: SUSE
名称: SUSE-SA:2006:050
链接:http://www.novell.com/linux/security/advisories/2006_50_imagemagick.html
来源: MANDRIVA
名称: MDKSA-2006:155
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:155
来源: DEBIAN
名称: DSA-1213
链接:http://www.debian.org/security/2006/dsa-1213
来源: SECTRACK
名称: 1016699
链接:http://securitytracker.com/id?1016699
来源: SREASON
名称: 1385
链接:http://securityreason.com/securityalert/1385
来源: GENTOO
名称: GLSA-200609-14
链接:http://security.gentoo.org/glsa/glsa-200609-14.xml
来源: SECUNIA
名称: 22998
链接:http://secunia.com/advisories/22998
来源: SECUNIA
名称: 22096
链接:http://secunia.com/advisories/22096
来源: SECUNIA
名称: 22036
链接:http://secunia.com/advisories/22036
来源: SECUNIA
名称: 21832
链接:http://secunia.com/advisories/21832
来源: SECUNIA
名称: 21679
链接:http://secunia.com/advisories/21679
来源: SECUNIA
名称: 21671
链接:http://secunia.com/advisories/21671
来源: SECUNIA
名称: 21621
链接:http://secunia.com/advisories/21621
来源: SECUNIA
名称: 21525
链接:http://secunia.com/advisories/21525
来源: MANDRIVA
名称: MDKSA-2006:155
链接:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:155
来源: SGI
名称: 20060901-01-P
链接:ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.asc