VDB
CVE-2008-1097
CVE-2008-1097
PUBLISHED
Reported by mitre · Published March 5, 2008
Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx.c in (1) ImageMagick 6.2.4-5 and 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .pcx file that triggers incorrect memory allocation for the scanline array, leading to memory corruption.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | *, *, n/a |
Exploit Intelligence
- https://bugzilla.redhat.com/show_bug.cgi?id=285861 (vulncheck-nvd)
Timeline
- Mar 5, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- GLSA-201311-10 vendor-advisoryx_refsource_GENTOO
- 28822 vdb-entryx_refsource_BID
- x_refsource_MISC
- 29857 third-party-advisoryx_refsource_SECUNIA
- RHSA-2008:0145 vendor-advisoryx_refsource_REDHAT
- 43213 vdb-entryx_refsource_OSVDB
- 1019881 vdb-entryx_refsource_SECTRACK
- 55721 third-party-advisoryx_refsource_SECUNIA
- 29786 third-party-advisoryx_refsource_SECUNIA
- x_refsource_CONFIRM
- 30967 third-party-advisoryx_refsource_SECUNIA
- oval:org.mitre.oval:def:11237 vdb-entrysignaturex_refsource_OVAL
- RHSA-2008:0165 vendor-advisoryx_refsource_REDHAT
- SUSE-SR:2008:014 vendor-advisoryx_refsource_SUSE
- MDVSA-2008:099 vendor-advisoryx_refsource_MANDRIVA
- DSA-1858 vendor-advisoryx_refsource_DEBIAN
- imagemagick-readpcximage-bo(41193) vdb-entryx_refsource_XF
- 36260 third-party-advisoryx_refsource_SECUNIA