VDB
CVE-2008-1096
CVE-2008-1096
PUBLISHED
Reported by mitre · Published March 5, 2008
The load_tile function in the XCF coder in coders/xcf.c in (1) ImageMagick 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .xcf file that triggers an out-of-bounds heap write, possibly related to the ScaleCharToQuantum function.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | n/a, n/a, n/a |
Exploit Intelligence
- https://bugzilla.redhat.com/show_bug.cgi?id=286411 (vulncheck-nvd)
Timeline
- Mar 5, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Dec 22, 2023 EPSS Score
References
- imagemagick-loadtile-code-execution(41194) vdb-entryx_refsource_XF
- 32945 third-party-advisoryx_refsource_SECUNIA
- RHSA-2008:0145 vendor-advisoryx_refsource_REDHAT
- 28821 vdb-entryx_refsource_BID
- 43212 vdb-entryx_refsource_OSVDB
- 29786 third-party-advisoryx_refsource_SECUNIA
- 30967 third-party-advisoryx_refsource_SECUNIA
- x_refsource_MISC
- SUSE-SR:2008:014 vendor-advisoryx_refsource_SUSE
- MDVSA-2008:099 vendor-advisoryx_refsource_MANDRIVA
- 1019880 vdb-entryx_refsource_SECTRACK
- DSA-1858 vendor-advisoryx_refsource_DEBIAN
- x_refsource_MISC
- oval:org.mitre.oval:def:10843 vdb-entrysignaturex_refsource_OVAL
- USN-681-1 vendor-advisoryx_refsource_UBUNTU
- 36260 third-party-advisoryx_refsource_SECUNIA