Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.51993
Categoría:Mandrake Local Security Checks
Título:Mandrake Security Advisory MDKSA-2005:065 (ImageMagick)
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing an update to ImageMagick
announced via advisory MDKSA-2005:065.

A format string vulnerability was discovered in ImageMagick, in the
way it handles filenames. An attacker could execute arbitrary code on
a victim's machine provided they could trick them into opening a file
with a special name (CVE-2005-0397).

As well, Andrei Nigmatulin discovered a heap-based buffer overflow in
ImageMagick's image handler. An attacker could create a special
PhotoShop Document (PSD) image file in such a way that it would cause
ImageMagick to execute arbitray code when processing the image
(CVE-2005-0005).

Other vulnerabilities were discovered in ImageMagick versions prior
to 6.0:

A bug in the way that ImageMagick handles TIFF tags was discovered.
It was possible that a TIFF image with an invalid tag could cause
ImageMagick to crash (CVE-2005-0759).

A bug in ImageMagick's TIFF decoder was discovered where a specially-
crafted TIFF image could cause ImageMagick to crash (CVE-2005-0760).

A bug in ImageMagick's PSD parsing was discovered where a specially-
crafted PSD file could cause ImageMagick to crash (CVE-2005-0761).

Finally, a heap overflow bug was discovered in ImageMagick's SGI
parser. If an attacker could trick a user into opening a specially-
crafted SGI image file, ImageMagick would execute arbitrary code
(CVE-2005-0762).

The updated packages have been patched to correct these issues.

Affected versions: 10.0, 10.1, Corporate 3.0,
Corporate Server 2.1

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2005:065

Risk factor : High

CVSS Score:
7.5

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2005-0397
20050303 [USN-90-1] Imagemagick vulnerability
http://marc.info/?l=bugtraq&m=110987256010857&w=2
DSA-702
http://www.debian.org/security/2005/dsa-702
GLSA-200503-11
http://www.gentoo.org/security/en/glsa/glsa-200503-11.xml
RHSA-2005:070
http://www.redhat.com/support/errata/RHSA-2005-070.html
RHSA-2005:320
http://www.redhat.com/support/errata/RHSA-2005-320.html
SUSE-SA:2005:017
http://www.novell.com/linux/security/advisories/2005_17_imagemagick.html
http://bugs.gentoo.org/show_bug.cgi?id=83542
imagemagick-filename-format-string(19586)
https://exchange.xforce.ibmcloud.com/vulnerabilities/19586
oval:org.mitre.oval:def:10302
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10302
Common Vulnerability Exposure (CVE) ID: CVE-2005-0005
Bugtraq: 20050118 [USN-62-1] imagemagick vulnerability (Google Search)
http://marc.info/?l=bugtraq&m=110608222117215&w=2
Debian Security Information: DSA-646 (Google Search)
http://www.debian.org/security/2005/dsa-646
http://www.gentoo.org/security/en/glsa/glsa-200501-37.xml
http://www.idefense.com/application/poi/display?id=184&type=vulnerabilities
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9925
http://www.redhat.com/support/errata/RHSA-2005-071.html
Common Vulnerability Exposure (CVE) ID: CVE-2005-0759
1013550
http://securitytracker.com/id?1013550
12875
http://www.securityfocus.com/bid/12875
https://rhn.redhat.com/errata/RHSA-2005-070.html
oval:org.mitre.oval:def:11022
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11022
Common Vulnerability Exposure (CVE) ID: CVE-2005-0760
oval:org.mitre.oval:def:11184
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11184
Common Vulnerability Exposure (CVE) ID: CVE-2005-0761
12876
http://www.securityfocus.com/bid/12876
http://rhn.redhat.com/errata/RHSA-2005-070.html
oval:org.mitre.oval:def:11150
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11150
Common Vulnerability Exposure (CVE) ID: CVE-2005-0762
oval:org.mitre.oval:def:9736
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9736
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.