Multiple Vendor ImageMagick .psd Image File Decode Heap Overflow Vulnerability
- 0
- Add a Comment
- No Related Post
iDEFENSE Security Advisory 01.17.05
ImageMagick provides a variety of graphics image-handling libraries and capabilities. These libraries are widely used and are shipped by default on most Unix and Linux distributions. These libraries are commonly installed by default on computers where any other graphical image viewer or X Desktop environment is installed (such as Gnome or KDE)….
Remote exploitation of a buffer overflow vulnerability in The ImageMagick’s Project’s ImageMagick PSD image-decoding module could allow an attacker to execute arbitrary code.
A heap overflow exists within ImageMagick, specifically in the decoding of Photoshop Document (PSD) files. The vulnerable code follows…
Exploitation may allow attackers to run arbitrary code on a victim’s computer if the victim opens a specially formatted image. Such images could be delivered by e-mail or HTML, in some cases, and would likely not raise suspicion on the victim’s part. Exploitation is also possible when a web-based application uses ImageMagick to process user-uploaded image files….
iDEFENSE has confirmed this vulnerability in ImageMagick 6.1.0 and
ImageMagick 6.1.7. Earlier versions are also suspected vulnerable.
The following vendors may include vulnerable ImageMagick packages:
The Debian Project
MandrakeSoft
Red Hat, Inc.
V. WORKAROUND
Do not open files from untrusted sources. Do not allow untrusted sources to process images using your web application.
VI. VENDOR RESPONSE
This vulnerability is addressed in ImageMagick 6.1.8-8, available for
download at:
http://www.imagemagick.org/www/download.html
