Register | Forget Password | Login
Search :
SecurityReason

News

Search

SecurityAlert

About SecurityAlert

ExploitAlert

SecurityReason Research

WLB

WLB Database

Send to WLB

About WLB

RSS

News

SecurityAlert

World Laboratory of Bugtraq

ExploitAlert

Apache

PHP

Corporate

Contact

About us

Services

SecurePHP

Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Details : SecurityAlert

  Topic : ImageMagick ReadSGIImage() Heap Overflow
  SecurityAlert : 1385
  CVE : CVE-2006-4144
  SecurityRisk : Medium  alert  (About)
  Remote Exploit : Yes
  Local Exploit : No
  Exploit Given : Yes
  Credit : Damian Put
  Published : 16.08.2006

  Affected Software : ImageMagick



  Advisory Text :  

Overflow.pl Security Advisory #7

ImageMagick ReadSGIImage() Heap Overflow

Vendor: ImageMagick (http://www.imagemagick.org)
Affected version: 6.x up to and including 6.2.8
Vendor status: Fixed version released (6.2.9)

Author: Damian Put <pucik (at) overflow (dot) pl [email concealed]>
URL: http://www.overflow.pl/adv/imsgiheap.txt
Date: 14.08.2006

1. Background

ImageMagick is a free software suite to create, edit, and compose bitmap
images.
It can read, convert and write images in a large variety of formats.

http://www.imagemagick.org

2. Description

Remote exploitation of a heap overflow vulnerability could allow execution
of
arbitrary code or couse denial of service.

A heap overflow exists in ReadSGIImage() function, that is used to
decode a SGI image file. The vulnerable code is:

coders/sgi.c:

static Image *ReadSGIImage(const ImageInfo *image_info,ExceptionInfo
*exception)
{
...
iris_info.bytes_per_pixel=(unsigned char) ReadBlobByte(image);
...
image->columns=iris_info.columns;
image->rows=iris_info.rows;
...
bytes_per_pixel=(size_t) iris_info.bytes_per_pixel;
number_pixels=(MagickSizeType) iris_info.columns*iris_info.rows;
...
iris_pixels=(unsigned char *)AcquireMagickMemory
(4*bytes_per_pixel*iris_info.columns*iris_info.rows);

We can manipalute iris_info.rows, iris_info.columns and bytes_per_pixel
value. Allocation of memory to "iris_pixels" is based on this values.
When rows*cols*bytes_per_pixe*4 overflow integer variable, we can alloc
not
enough memory for next operations, and cause heap overflow.

3. PoC

Example crafted SGI file: http://overflow.pl/poc/imheap.sgi

[pucik@overflow ImageMagick-6.2.8]$ display imheap.sgi
*** glibc detected *** free(): invalid next size (fast): 0x08055dd0 ***
Abort (core dumped)
[pucik@overflow ImageMagick-6.2.8]$




  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

Microsoft VISTA TCP/IP stack buffer overflow

high- 2008-11-27

Microsoft Device IO Control wrapped by the iphlpapi.dll API shipping with Windows Vista 32 bit and 64 bit contains a possibly exploitable, buffer overflow corrupting kernel memory.

Apache rss

» Apache Tomcat information
   disclosure

» Apache Tomcat <=
   6.0.18 UTF8 Directory
   Traversal Vulnerability

» Apache Tomcat information
   disclosure vulnerability

» Apache Tomcat XSS
   vulnerability

PHP rss

» PHP 5.2.6 dba_replace()
   destroying file

» PHP 5.2.6 (error_log)
   safe_mode bypass

» PHP 5.2.6 chdir(),ftok()
   (standard ext) safe_mode
   bypass

» PHP 5.2.6 posix_access()
   (posix ext) safe_mode
   bypass

Copyright © SecurityReason. All Rights Reserved.