First published: Wed Nov 16 2005(Updated: )
ImageMagick before 6.2.4.2-r1 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick | =4.2.7 | |
ImageMagick | =5.5.4.4 | |
ImageMagick | =6.2.2.5 | |
ImageMagick | =6.1.9.4 | |
ImageMagick | =6.1.3.7 | |
ImageMagick | =6.2.0.8 | |
ImageMagick | =5.5.7.31 | |
ImageMagick | =5.3.2 | |
ImageMagick | =6.0.6.2 | |
ImageMagick | =5.5.7q16 | |
ImageMagick | =6.0 | |
ImageMagick | =4.2.9 | |
ImageMagick | =5.3.4 | |
ImageMagick | =6.0.3.5 | |
ImageMagick | =6.2.3.6 | |
ImageMagick | =6.1.8.7 | |
ImageMagick | =5.4.5.1 | |
ImageMagick | =5.3.7 | |
ImageMagick | =6.0.5.3 | |
ImageMagick | =6.1.4.5 | |
ImageMagick | =6.1.6.9 | |
ImageMagick | =6.1.2.7 | |
ImageMagick | =5.2.0 | |
ImageMagick | =5.3.0 | |
ImageMagick | =5.5.2.5 | |
ImageMagick | =6.1.0.9 | |
ImageMagick | =5.5.3.2 | |
ImageMagick | =5.5.6 | |
ImageMagick | =6.0.4.4 | |
ImageMagick | =5.4.1.2 | |
ImageMagick | =5.3.1 | |
ImageMagick | =5.3.6 | |
ImageMagick | =5.2.6 | |
ImageMagick | =5.4.4.5 | |
ImageMagick | =5.4.6.3 | |
ImageMagick | =6.0.7.3 | |
ImageMagick | =5.5.7.35 | |
ImageMagick | =5.4.3.11 | |
ImageMagick | =5.3.8.2 | |
ImageMagick | =5.4.8.3 | |
ImageMagick | =6.2.1.7 | |
ImageMagick | =6.0.2.7 | |
ImageMagick | =6.0.0.7 | |
ImageMagick | =5.3.3 | |
ImageMagick | =5.4.0.5 | |
ImageMagick | =5.4.9.1 | |
ImageMagick | =5.5.7q8 | |
ImageMagick | =6.0.1.4 | |
ImageMagick | =5.3.9 | |
ImageMagick | =5.4.2.3 | |
ImageMagick | =5.3.5 | |
ImageMagick | =6.1.1.6 | |
ImageMagick | =5.5.5.3 | |
ImageMagick | =6.1.5.8 | |
ImageMagick | =6.1.7.5 | |
ImageMagick | =5.4.7.4 | |
ImageMagick | =6.0.8.3 | |
ImageMagick | =5.5.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3582 is considered a high-severity vulnerability due to its potential to allow local users to escalate privileges.
CVE-2005-3582 exploits ImageMagick by allowing local users in the portage group to load shared objects from a insecure temporary build directory.
CVE-2005-3582 affects multiple versions of ImageMagick, specifically those before 6.2.4.2-r1, including versions 4.2.7, 5.5.4.4, and various 6.x versions.
To fix CVE-2005-3582, upgrade ImageMagick to a version that is patched against this vulnerability, specifically 6.2.4.2-r1 or newer.
No, CVE-2005-3582 is not a concern for current versions of ImageMagick that have been updated beyond the vulnerable release.