CVE-2007-4987

Impact:
Low
Public Date:
2007-09-19
Bugzilla:
310101: CVE-2007-4987 ImageMagick writes terminating NUL one byte beyond char array end

The MITRE CVE dictionary describes this issue as:

Off-by-one error in the ReadBlobString function in blob.c in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted image file, which triggers the writing of a '\0' character to an out-of-bounds address.

Find out more about CVE-2007-4987 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Note: As the address of the overwritten byte is not under attackers control, the worst impact his bug could have is an application crash. It can not be exploited to execute arbitrary code.

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.