Summary
The remote host is missing an update to imagemagic announced via advisory DSA 547-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20547-1
Insight
Marcus Meissner from SUSE has discovered several buffer overflows in the ImageMagick graphics library. An attacker could create a malicious image or video file in AVI, BMP, or DIB format that could crash the reading process. It might be possible that carefully crafted images could also allow to execute arbitrary code with the capabilities of the invoking process.
For the stable distribution (woody) this problem has been fixed in version 5.4.4.5-1woody3.
For the unstable distribution (sid) this problem has been fixed in version 6.0.6.2-1.
We recommend that you upgrade your imagemagick packages.
Severity
Classification
-
CVE CVE-2004-0827 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities