Back

HIGH

ImageMagick writes terminating NUL one byte beyond char array end

Published Sep 24, 2007

Description

Off-by-one error in the ReadBlobString function in blob.c in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted image file, which triggers the writing of a '\0' character to an out-of-bounds address.

Affected products

Remediation

Red Hat statement

Note: As the address of the overwritten byte is not under attackers control, the worst impact his bug could have is an application crash. It can not be exploited to execute arbitrary code.

Metrics

Weaknesses (1)

References (26)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 24, 2007
Updated Aug 7, 2024
Reserved Sep 19, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Sep 19, 2007