Description
ImageMagick before 6.0 allows remote attackers to cause a denial of service (application crash) via a TIFF image with an invalid tag.
Product(s):
- ImageMagick 5.3.3
- ImageMagick 5.3.8
- ImageMagick 5.4.3
- ImageMagick 5.4.4.5
- ImageMagick 5.4.7
- ImageMagick ImageMagick 5.4.8.2.1.1.0
- ImageMagick 5.4.8
- ImageMagick 5.5.3.2.1.2.0
- ImageMagick 5.5.4
- ImageMagick 5.5.6.0 2003-04-09
- ImageMagick 5.5.6
- ImageMagick 5.5.7
- SGI ProPack 3.0
Question to Ask Vendors:
- Can you confirm whether your systems are affected by CVE-2005-0759, and if so, what steps are you currently taking to mitigate this vulnerability?
- What is your estimated timeline for fully resolving CVE-2005-0759 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions:
- Check out the advisory links provided below.