iDefense Security Advisory 03.31.07 – Remote exploitation of several buffer overflow vulnerabilities in ImageMagick, as included in various vendors’ operating system distributions, allows attackers to execute arbitrary code with the credentials used for image processing. An integer overflow exists ImageMagick’s handling of DCM (Digital Imaging and Communications in Medicine) format files which allows an attacker to cause a heap-based buffer overflow. This vulnerability specifically exists in the ReadDCMImage() function. Two integer overflows exists ImageMagick’s handling of XWD (X Windows Dump) format files that allows an attacker to cause a heap-based buffer overflow. The vulnerabilities specifically exist in the ReadXWDImage() function. An integer overflow could occur when calculating the amount of memory to allocate for the ‘colors’ or ‘comment’ field. iDefense has confirmed the existence of these vulnerabilities in ImageMagick version 6.3.x. Additionally, the source code for versions 6.3.1, 6.3.2, 6.3.3-3 and 6.2.9 contain the affected code. It is suspected that earlier versions of ImageMagick are also vulnerable.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/55556/03.31.07-1.txt
Source: https://packetstormsecurity.com/files/55556/iDEFENSE-Security-Advisory-2007-03-31.1.html