[UNIX] ImageMagic SGI Buffer Overflow, PSD/TIFF DoS and Filename Format String
From: SecuriTeam (support_at_securiteam.com)
Date: 03/24/05
- Previous message: SecuriTeam: "[NEWS] Samsung ADSL Modem Arbitrary File Access, Default Root Password and Root File System Access"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: list@securiteam.com Date: 24 Mar 2005 19:18:09 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
ImageMagic SGI Buffer Overflow, PSD/TIFF DoS and Filename Format String
------------------------------------------------------------------------
SUMMARY
<http://www.imagemagick.org/> ImageMagickTM, "is a free software suite
for the creation, modification and display of bitmap images".
ImageMagic contain vulnerabilities that allow attacker to cause the
program to execute arbitrary code by exploiting a problem caused by poor
sanitization of the filename and allows attackers to crash ImageMagic by
making it process specially crafted image files.
DETAILS
Vulnerable Systems:
* ImageMagic version 6.1.8 and prior
Immune Systems:
* ImageMagic version 6.2.0
Format String:
The format string vulnerability allows remote attackers to execute code
as the user running display by providing handcrafted filenames of images.
Buffer Overflow:
An heap overflow was found in ImageMagick's SGI parser. It is possible
that an attacker can leverage this to cause the program to execute
arbitrary code by tricking a user into opening a specially crafted SGI
image file.
Denial of Service:
A specially crafted TIFF image or an invalid TIFF tag can be used to cause
ImageMagick to crash. The ImageMagick parser of PSD files can be used to
cause ImageMagic to crash by suppling it with a specially crafted PSD
file.
Vendor Status:
A new version of ImageMagic is available at:
<http://www.imagemagick.org/> http://www.imagemagick.org/.
CVE Information:
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0397>
CAN-2005-0397
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0759>
CAN-2005-0759
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0760>
CAN-2005-0760
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0761>
CAN-2005-0761
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0762>
CAN-2005-0762
ADDITIONAL INFORMATION
The information has been provided by <mailto:meissner@suse.de> Marcus
Meissner.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: SecuriTeam: "[NEWS] Samsung ADSL Modem Arbitrary File Access, Default Root Password and Root File System Access"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
- [NEWS] Multiple Vendor ImageMagick DCM and XWD Buffer Overflow Vulnerabilities
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Multiple Vendor ImageMagick
DCM and XWD Buffer Overflow Vulnerabilities ... (Securiteam) - [UNIX] Multiple Vendor ImageMagick Multiple Integer Overflow Vulnerabilities
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Multiple Vendor ImageMagick
Multiple Integer Overflow Vulnerabilities ... to open a malicious image file with a
program that utilizes the ... (Securiteam) - [UNIX] Multiple Vendor ImageMagick Multiple Denial of Service Vulnerabilities
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Multiple Vendor ImageMagick
Multiple Denial of Service Vulnerabilities ... (Securiteam) - [UNIX] Multiple Vendor ImageMagick Sign Extension Vulnerability
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Multiple Vendor ImageMagick
Sign Extension Vulnerability ... (Securiteam) - [UNIX] phpSysInfo Multiple Vulnerabilities (HTTP_ACCEPT_LANGUAGE, sensor_program, VERSION, charset)
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Multiple vulnerabilities have
been discovered in phpSysInfo allowing ... the attacker to additionally inject the
$lng parameter. ... $sensor_program can *still* be used to inject active ... (Securiteam)