CVE-2006-2440

NameCVE-2006-2440
DescriptionHeap-based buffer overflow in the libMagick componet of ImageMagick 6.0.6.2 might allow attackers to execute arbitrary code via an image index array that triggers the overflow during filename glob expansion by the ExpandFilenames function.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-1168-1
NVD severityhigh (attack range: remote)
Debian Bugs345595
Debian/oldoldstablenot vulnerable.
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
imagemagick (PTS)squeeze, squeeze (security)8:6.6.0.4-3+squeeze4fixed
squeeze (lts)8:6.6.0.4-3+squeeze5fixed
wheezy, wheezy (security)8:6.7.7.10-5+deb7u3fixed
stretch, sid, jessie8:6.8.9.9-5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
imagemagicksource(unstable)6:6.2.4.5-0.6high345595
imagemagicksourcesarge6:6.0.6.2-2.7highDSA-1168-1

Search for package or bug name: Reporting problems