CVE-2006-2440

NameCVE-2006-2440
DescriptionHeap-based buffer overflow in the libMagick componet of ImageMagick 6.0.6.2 might allow attackers to execute arbitrary code via an image index array that triggers the overflow during filename glob expansion by the ExpandFilenames function.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-1168-1
NVD severityhigh (attack range: remote)
Debian Bugs345595

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
imagemagick (PTS)wheezy8:6.7.7.10-5+deb7u4fixed
wheezy (security)8:6.7.7.10-5+deb7u15fixed
jessie8:6.8.9.9-5+deb8u9fixed
jessie (security)8:6.8.9.9-5+deb8u10fixed
stretch8:6.9.7.4+dfsg-11fixed
stretch (security)8:6.9.7.4+dfsg-11+deb9u1fixed
buster, sid8:6.9.7.4+dfsg-12fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
imagemagicksource(unstable)6:6.2.4.5-0.6high345595
imagemagicksourcesarge6:6.0.6.2-2.7highDSA-1168-1

Search for package or bug name: Reporting problems