CVE Vulnerabilities

CVE-2007-1667

Published: Mar 24, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Multiple integer overflows in (1) the XGetPixel function in ImUtil.c in X.Org libx11 before 1.0.3, and (2) XInitImage function in xwd.c for ImageMagick, allow user-assisted remote attackers to cause a denial of service (crash) or obtain sensitive information via crafted images with large or negative values that trigger a buffer overflow.

Affected Software

NameVendorStart VersionEnd Version
Libx11X.org*1.0.2 (including)
Red Hat Enterprise Linux 2.1RedHatXFree86-0:4.1.0-82.EL*
Red Hat Enterprise Linux 3RedHatXFree86-0:4.3.0-120.EL*
Red Hat Enterprise Linux 4RedHatxorg-x11-0:6.8.2-1.EL.13.37.7*
Red Hat Enterprise Linux 5RedHatlibX11-0:1.0.3-8.0.1.el5*
Red Hat Enterprise Linux 5RedHatxorg-x11-apps-0:7.1-4.0.1.el5*
GraphicsmagickUbuntudevel*
GraphicsmagickUbuntuedgy*
GraphicsmagickUbuntufeisty*
GraphicsmagickUbuntugutsy*
GraphicsmagickUbuntuhardy*
ImagemagickUbuntudapper*
ImagemagickUbuntudevel*
ImagemagickUbuntuedgy*
ImagemagickUbuntufeisty*
ImagemagickUbuntugutsy*
ImagemagickUbuntuhardy*
Libx11Ubuntudapper*
Libx11Ubuntudevel*
Libx11Ubuntuedgy*
Libx11Ubuntufeisty*
Libx11Ubuntugutsy*
Libx11Ubuntuhardy*

References