vendor:
ImageMagick
by:
Mike Czumak (T_v3rn1x)
7,8
CVSS
HIGH
Local Buffer Overflow (SEH)
119
CWE
Product Name: ImageMagick
Affected Version From: 6.8.8-4
Affected Version To: 6.8.8-5
Patch Exists: YES
Related CWE: CVE-2014-1947
CPE: a:imagemagick:imagemagick
Metasploit:
https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2014-1947/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2014-2030/, https://www.rapid7.com/db/vulnerabilities/amazon-linux-ami-alas-2014-420/, https://www.rapid7.com/db/vulnerabilities/amazon-linux-ami-alas-2014-336/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2014-2030/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2014-1947/, https://www.rapid7.com/db/vulnerabilities/debian-DSA-2898/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2014-1947/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2014-2030/, https://www.rapid7.com/db/vulnerabilities/ubuntu-USN-2132-1/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2014
ImageMagick < 6.8.8-5 - Local Buffer Overflow (SEH)
This particular BOF takes advantage of insecure handling of the english.xml file which the app uses to display various error messages. This script generates two files: a malfored .bmp file that will cause ImageMagick to generate a specific error when opened (LengthAndFilesizeDoNotMatch), as defined in the english.xml file and a modified english.xml file that replaces the original error message with our exploit code.
Mitigation:
Update ImageMagick to version 6.8.8-5 or later.