Vulnerability Description
Integer overflow in the ReadSGIImage function in sgi.c in ImageMagick before 6.2.9 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via large (1) bytes_per_pixel, (2) columns, and (3) rows values, which trigger a heap-based buffer overflow.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Imagemagick | Imagemagick | 6.0.1 |
References
- ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.asc
- http://secunia.com/advisories/21462PatchVendor Advisory
- http://secunia.com/advisories/21525
- http://secunia.com/advisories/21621
- http://secunia.com/advisories/21671
- http://secunia.com/advisories/21679
- http://secunia.com/advisories/21832
- http://secunia.com/advisories/22036
- http://secunia.com/advisories/22096
- http://secunia.com/advisories/22998
- http://security.gentoo.org/glsa/glsa-200609-14.xml
- http://securityreason.com/securityalert/1385
- http://securitytracker.com/id?1016699
- http://www.debian.org/security/2006/dsa-1213
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:155
FAQ
What is CVE-2006-4144?
CVE-2006-4144 is a vulnerability with a CVSS score of 2.6 (LOW). Integer overflow in the ReadSGIImage function in sgi.c in ImageMagick before 6.2.9 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via large (1)...
How severe is CVE-2006-4144?
CVE-2006-4144 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-4144?
Check the references section above for vendor advisories and patch information. Affected products include: Imagemagick Imagemagick.