CVE-2006-5456
EPSS 0.85%
Description
Multiple buffer overflows in GraphicsMagick before 1.1.7 and ImageMagick 6.0.7 allow user-assisted attackers to cause a denial of service and possibly execute arbitrary code via (1) a DCM image that is not properly handled by the ReadDCMImage function in coders/dcm.c, or (2) a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c.
How to fix CVE-2006-5456
To remediate CVE-2006-5456, upgrade the affected package to a fixed version below.
- Debian/graphicsmagick—upgrade to 1.1.7-9 or later
- Debian/imagemagick—upgrade to 7:6.2.4.5.dfsg1-0.11 or later
Is CVE-2006-5456 being exploited?
Low — EPSS is 0.9%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 1.1.7-9
- from 0, < 7:6.2.4.5.dfsg1-0.11