Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:
Category:Red Hat Local Security Checks
Title:RedHat Security Advisory RHSA-2006:0633

The remote host is missing updates announced in
advisory RHSA-2006:0633.

ImageMagick(TM) is an image display and manipulation tool for the X Window
System that can read and write multiple image formats.

Tavis Ormandy discovered several integer and buffer overflow flaws in the
way ImageMagick decodes XCF, SGI, and Sun bitmap graphic files. An attacker
could execute arbitrary code on a victim's machine if they were able to
trick the victim into opening a specially crafted image file.
(CVE-2006-3743, CVE-2006-3744, CVE-2006-4144)

Users of ImageMagick should upgrade to these updated packages, which
contain backported patches and are not vulnerable to these issues.

Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

Risk factor : High

CVSS Score:

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2006-3743
BugTraq ID: 19697
Debian Security Information: DSA-1168 (Google Search)
SGI Security Advisory: 20060901-01-P
SuSE Security Announcement: SUSE-SA:2006:050 (Google Search)
XForce ISS Database: imagemagick-propuserunit-bo(28575)
Common Vulnerability Exposure (CVE) ID: CVE-2006-3744
BugTraq ID: 19699
XForce ISS Database: imagemagick-rasterfile-bo(28574)
Common Vulnerability Exposure (CVE) ID: CVE-2006-4144
BugTraq ID: 19507
Bugtraq: 20060814 [] ImageMagick ReadSGIImage() Heap Overflow (Google Search)
Bugtraq: 20060816 Re: [] ImageMagick ReadSGIImage() Heap Overflow (Google Search)
Debian Security Information: DSA-1213 (Google Search)
XForce ISS Database: imagemagick-readsgiimage-bo(28372)
CopyrightCopyright (c) 2006 E-Soft Inc.

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.

© 1998-2021 E-Soft Inc. All rights reserved.