CVE-2006-5456
EPSS 3.5%
描述
Multiple buffer overflows in GraphicsMagick before 1.1.7 and ImageMagick 6.0.7 allow user-assisted attackers to cause a denial of service and possibly execute arbitrary code via (1) a DCM image that is not properly handled by the ReadDCMImage function in coders/dcm.c, or (2) a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c.
如何修補 CVE-2006-5456
要修補 CVE-2006-5456,請將受影響套件升級到下列已修補版本。
- Debian/graphicsmagick—升級至 1.1.7-9 或更新版本
- Debian/imagemagick—升級至 7:6.2.4.5.dfsg1-0.11 或更新版本
CVE-2006-5456 正在被利用嗎?
低 — EPSS 為 3.5%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 1.1.7-9
- from 0, < 7:6.2.4.5.dfsg1-0.11