CVE-2006-2440

NameCVE-2006-2440
DescriptionHeap-based buffer overflow in the libMagick componet of ImageMagick 6.0.6.2 might allow attackers to execute arbitrary code via an image index array that triggers the overflow during filename glob expansion by the ExpandFilenames function.
SourceCVE (at NVD; LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-1168-1
NVD severityhigh (attack range: remote)
Debian Bugs345595

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
imagemagick (PTS)wheezy8:6.7.7.10-5+deb7u3fixed
wheezy (security)8:6.7.7.10-5+deb7u4fixed
jessie8:6.8.9.9-5+deb8u1fixed
stretch, sid8:6.8.9.9-7fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
imagemagicksource(unstable)6:6.2.4.5-0.6high345595
imagemagicksourcesarge6:6.0.6.2-2.7highDSA-1168-1

Search for package or bug name: Reporting problems