CVE Vulnerabilities

CVE-2007-4987

Published: Sep 24, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Off-by-one error in the ReadBlobString function in blob.c in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted image file, which triggers the writing of a 0 character to an out-of-bounds address.

Affected Software

NameVendorStart VersionEnd Version
ImagemagickImagemagick5.3.3 (including)5.3.3 (including)
ImagemagickImagemagick5.3.8 (including)5.3.8 (including)
ImagemagickImagemagick5.4.2.3 (including)5.4.2.3 (including)
ImagemagickImagemagick5.4.3 (including)5.4.3 (including)
ImagemagickImagemagick5.4.4.5 (including)5.4.4.5 (including)
ImagemagickImagemagick5.4.7 (including)5.4.7 (including)
ImagemagickImagemagick5.4.8 (including)5.4.8 (including)
ImagemagickImagemagick5.4.8.2_1.1.0 (including)5.4.8.2_1.1.0 (including)
ImagemagickImagemagick5.5.3_.2_1.2.0 (including)5.5.3_.2_1.2.0 (including)
ImagemagickImagemagick5.5.4 (including)5.5.4 (including)
ImagemagickImagemagick5.5.6 (including)5.5.6 (including)
ImagemagickImagemagick5.5.6.0_20030409 (including)5.5.6.0_20030409 (including)
ImagemagickImagemagick5.5.7 (including)5.5.7 (including)
ImagemagickImagemagick5.5.7.15 (including)5.5.7.15 (including)
ImagemagickImagemagick6.0 (including)6.0 (including)
ImagemagickImagemagick6.0.1 (including)6.0.1 (including)
ImagemagickImagemagick6.0.2 (including)6.0.2 (including)
ImagemagickImagemagick6.0.2.5 (including)6.0.2.5 (including)
ImagemagickImagemagick6.0.3 (including)6.0.3 (including)
ImagemagickImagemagick6.0.4 (including)6.0.4 (including)
ImagemagickImagemagick6.0.4.4 (including)6.0.4.4 (including)
ImagemagickImagemagick6.0.5 (including)6.0.5 (including)
ImagemagickImagemagick6.0.6 (including)6.0.6 (including)
ImagemagickImagemagick6.0.6.2 (including)6.0.6.2 (including)
ImagemagickImagemagick6.0.7 (including)6.0.7 (including)
ImagemagickImagemagick6.0.8 (including)6.0.8 (including)
ImagemagickImagemagick6.1 (including)6.1 (including)
ImagemagickImagemagick6.1.1 (including)6.1.1 (including)
ImagemagickImagemagick6.1.2 (including)6.1.2 (including)
ImagemagickImagemagick6.1.3 (including)6.1.3 (including)
ImagemagickImagemagick6.1.4 (including)6.1.4 (including)
ImagemagickImagemagick6.1.5 (including)6.1.5 (including)
ImagemagickImagemagick6.1.6 (including)6.1.6 (including)
ImagemagickImagemagick6.1.7 (including)6.1.7 (including)
ImagemagickImagemagick6.1.8 (including)6.1.8 (including)
ImagemagickImagemagick6.2 (including)6.2 (including)
ImagemagickImagemagick6.2.0.3 (including)6.2.0.3 (including)
ImagemagickImagemagick6.2.0.7 (including)6.2.0.7 (including)
ImagemagickImagemagick6.2.1 (including)6.2.1 (including)
ImagemagickImagemagick6.2.2 (including)6.2.2 (including)
ImagemagickImagemagick6.2.3 (including)6.2.3 (including)
ImagemagickImagemagick6.2.3.4 (including)6.2.3.4 (including)
ImagemagickImagemagick6.2.4 (including)6.2.4 (including)
ImagemagickImagemagick6.2.4.3 (including)6.2.4.3 (including)
ImagemagickImagemagick6.2.4.5 (including)6.2.4.5 (including)
ImagemagickImagemagick6.2.5 (including)6.2.5 (including)
ImagemagickImagemagick6.2.6 (including)6.2.6 (including)
ImagemagickImagemagick6.2.7 (including)6.2.7 (including)
ImagemagickImagemagick6.2.8 (including)6.2.8 (including)
ImagemagickImagemagick6.2.9 (including)6.2.9 (including)
ImagemagickImagemagick6.2.9.2 (including)6.2.9.2 (including)
ImagemagickImagemagick6.3.1 (including)6.3.1 (including)
ImagemagickImagemagick6.3.2 (including)6.3.2 (including)
ImagemagickImagemagick6.3.3_3 (including)6.3.3_3 (including)
ImagemagickImagemagick6.3.3_5 (including)6.3.3_5 (including)
ImagemagickImagemagick6.3.3_6 (including)6.3.3_6 (including)
ImagemagickImagemagick6.3.4 (including)6.3.4 (including)
ImagemagickUbuntudapper*
ImagemagickUbuntudevel*
ImagemagickUbuntuedgy*
ImagemagickUbuntufeisty*
ImagemagickUbuntugutsy*
ImagemagickUbuntuupstream*

References