6.8

CVE-2008-1097

Exploit

Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx.c in (1) ImageMagick 6.2.4-5 and 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .pcx file that triggers incorrect memory allocation for the scanline array, leading to memory corruption.

Data is provided by the National Vulnerability Database (NVD)
ImagemagickGraphicsmagick Version1.1.7
ImagemagickGraphicsmagick Version1.1.8
ImagemagickGraphicsmagick Version1.1.9
ImagemagickGraphicsmagick Version1.1.10
ImagemagickGraphicsmagick Version1.1.11
ImagemagickGraphicsmagick Version1.1.12
ImagemagickImagemagick Version6.2.8.0
ImagemagickImagemagick Version6.2.8.1
ImagemagickImagemagick Version6.2.8.2
ImagemagickImagemagick Version6.2.8.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 6% 0.901
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P