CERTA-2005-AVI-203
Vulnerability from certfr_avis
Une vulnérabilité dans ImageMagick et GraphicsMagick permet à un utilisateur distant mal intentionné de provoquer un déni de service.
Description
ImageMagick et GraphicsMagick sont des ensembles d'outils permettant la lecture, la création et la manipulation d'images dans de nombreux formats. Une erreur dans leurs décodeurs XWD (X Window Dump) permet à un utilisateur distant mal intentionné de provoquer un déni de service par le biais d'une image malicieusement constituée.
Solution
le version 6.2.2.3 de ImageMagick ainsi que la version 1.1.6-r1 de GraphicsMagick corrigent le problème.
NoneImpacted products
References
| Title | Publication Time | Tags | |
|---|---|---|---|
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [
{
"description": "GraphicsMagick versions ant\u00e9rieures \u00e0 1.1.6-r1.",
"product": {
"name": "N/A",
"vendor": {
"name": "N/A",
"scada": false
}
}
},
{
"description": "ImageMagick versions ant\u00e9rieures \u00e0 6.2.2.3 ;",
"product": {
"name": "N/A",
"vendor": {
"name": "N/A",
"scada": false
}
}
}
],
"affected_systems_content": null,
"content": "## Description\n\nImageMagick et GraphicsMagick sont des ensembles d\u0027outils permettant la\nlecture, la cr\u00e9ation et la manipulation d\u0027images dans de nombreux\nformats. Une erreur dans leurs d\u00e9codeurs XWD (X Window Dump) permet \u00e0 un\nutilisateur distant mal intentionn\u00e9 de provoquer un d\u00e9ni de service par\nle biais d\u0027une image malicieusement constitu\u00e9e.\n\n## Solution\n\nle version 6.2.2.3 de ImageMagick ainsi que la version 1.1.6-r1 de\nGraphicsMagick corrigent le probl\u00e8me.\n",
"cves": [],
"initial_release_date": "2005-06-13T00:00:00",
"last_revision_date": "2005-06-29T00:00:00",
"links": [
{
"title": "Bulletin de s\u00e9curit\u00e9 Gentoo GLSA-200505-16 du 21 mai 2005 :",
"url": "http://security.gentoo.org/glsa/glsa-200505-16.xml"
},
{
"title": "Bulletin de s\u00e9curit\u00e9 Mandriva MDKSA-2005:107 du 28 juin 2005 :",
"url": "http://www.mandriva.com/security/advisories?name=MDKSA-2005:107"
},
{
"title": "Mise \u00e0 jour de s\u00e9curit\u00e9 Fedora Core 3 pour ImageMagick du 26 mai 2005 :",
"url": "http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/"
}
],
"reference": "CERTA-2005-AVI-203",
"revisions": [
{
"description": "version initiale.",
"revision_date": "2005-06-13T00:00:00.000000"
},
{
"description": "Ajout r\u00e9f\u00e9rence \u00e0 la mise-\u00e0-jour Fedora. Ajout r\u00e9f\u00e9rence au bulletin de s\u00e9curit\u00e9 de Mandriva.",
"revision_date": "2005-06-29T00:00:00.000000"
}
],
"risks": [
{
"description": "D\u00e9ni de service"
}
],
"summary": "Une vuln\u00e9rabilit\u00e9 dans ImageMagick et GraphicsMagick permet \u00e0 un\nutilisateur distant mal intentionn\u00e9 de provoquer un d\u00e9ni de service.\n",
"title": "Vuln\u00e9rabilit\u00e9 d\u0027ImageMagick et GraphicsMagick",
"vendor_advisories": [
{
"published_at": null,
"title": "Bulletin de s\u00e9curit\u00e9 Gentoo GLSA 200505-16 du 21 mai 2005",
"url": null
}
]
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…