VulnerabilityModified
CVE-2004-0981
Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain image file.
HIGH 10.0EPSS 5.84%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.84%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain image file.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 5.84% probability · 93th percentile
- CISA KEV
- Not listed
- Affected
- imagemagick/imagemagick · debian/debian linux · gentoo/linux · suse/suse linux
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/12995/
- http://security.gentoo.org/glsa/glsa-200411-11.xml
- http://www.imagemagick.org/www/Changelog.html
- http://www.securityfocus.org/bid/11548
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17903
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10472
- https://www.ubuntu.com/usn/usn-7-1/
- http://secunia.com/advisories/12995/
- http://security.gentoo.org/glsa/glsa-200411-11.xml
- http://www.imagemagick.org/www/Changelog.html
- http://www.securityfocus.org/bid/11548
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17903
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10472
- https://www.ubuntu.com/usn/usn-7-1/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.