First published: Wed Jan 04 2006(Updated: )
Format string vulnerability in the SetImageInfo function in image.c for ImageMagick 6.2.3 and other versions, and GraphicsMagick, allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a numeric format string specifier such as %d in the file name, a variant of CVE-2005-0397, and as demonstrated using the convert program.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick ImageMagick | =6.2.3 |
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.341682
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.