CVE-2007-4987
Off-by-one error in the ReadBlobString function in blob.c in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted image file, which triggers the writing of a '\0' character to an out-of-bounds address.
- Affected products
- Imagemagick
- Imagemagick
- = 5.3.3, 5.3.8, 5.4.2.3, 5.4.3, 5.4.4.5, 5.4.7, 5.4.8, 5.4.8.2_1.1.0, 5.5.3_.2_1.2.0, 5.5.4, 5.5.6, 5.5.6.0_20030409, 5.5.7, 5.5.7.15, 6.0, 6.0.1, 6.0.2, 6.0.2.5, 6.0.3, 6.0.4, 6.0.4.4, 6.0.5, 6.0.6, 6.0.6.2, 6.0.7, 6.0.8, 6.1, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 6.1.8, 6.2, 6.2.0.3, 6.2.0.7, 6.2.1, 6.2.2
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 3.8% (89th percentile)
- Weakness
- CWE-189
- NVD status
- Modified
- Published
- 2007-09-24
CVE-2007-4987 at NVD
1 known exploit for CVE-2007-4987
Proof-of-concept code and exploit modules indexed by Sploitus