CVE-2006-4144

Publication date 15 August 2006

Last updated 24 July 2024


Ubuntu priority

Integer overflow in the ReadSGIImage function in sgi.c in ImageMagick before 6.2.9 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via large (1) bytes_per_pixel, (2) columns, and (3) rows values, which trigger a heap-based buffer overflow.

Status

Package Ubuntu Release Status
graphicsmagick 7.04 feisty
Fixed 1.1.7-8
6.10 edgy
Fixed 1.1.7-8
6.06 LTS dapper Not in release
imagemagick 7.04 feisty
Fixed 6.2.4.5.dfsg1-0.14ubuntu0.1
6.10 edgy
Fixed 6.2.4.5.dfsg1-0.10ubuntu0.3
6.06 LTS dapper
Fixed 6.2.4.5-0.6ubuntu0.6

References

Related Ubuntu Security Notices (USN)

    • USN-337-1
    • imagemagick vulnerability
    • 17 August 2006

Other references