First published: Thu May 18 2006(Updated: )
Heap-based buffer overflow in the libMagick component of ImageMagick 6.0.6.2 might allow attackers to execute arbitrary code via an image index array that triggers the overflow during filename glob expansion by the ExpandFilenames function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick | =6.0.6.2 | |
ImageMagick | =6.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2440 is classified as a critical vulnerability due to the potential for arbitrary code execution.
To fix CVE-2006-2440, update ImageMagick to version 6.2.5 or later.
CVE-2006-2440 affects ImageMagick versions 6.0.6.2 and 6.2.4.
The impact of CVE-2006-2440 allows attackers to execute arbitrary code, potentially compromising the affected system.
There are no effective workarounds for CVE-2006-2440, and updating the software is strongly recommended.