Back
CVE-2006-0082
Format string vulnerability in the SetImageInfo function in image.c for ImageMagick 6.2.3 and other versions, and GraphicsMagick, allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a numeric format string specifier such as %d in the file name, a variant of CVE-2005-0397, and as demonstrated using the convert program.
Published: Jan 4, 2006
Modified: Jun 16, 2026
CWE-134
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| imagemagick | imagemagick | 6.2.3 |
GitHub Security Advisory GHSA-gqwr-p67x-5fff
Format string vulnerability in the SetImageInfo function in image.c for ImageMagick 6.2.3 and...
References (56)
- ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc Patch
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345876 Exploit, Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2006-0178.html
- http://secunia.com/advisories/18261 Vendor Advisory
- http://secunia.com/advisories/18607 Patch, Vendor Advisory
- http://secunia.com/advisories/18851 Patch, Vendor Advisory
- http://secunia.com/advisories/18871 Vendor Advisory
- http://secunia.com/advisories/19030 Patch, Vendor Advisory
- http://secunia.com/advisories/19183 Patch, Vendor Advisory
- http://secunia.com/advisories/19408 Vendor Advisory
- http://secunia.com/advisories/22998 Vendor Advisory
- http://secunia.com/advisories/23090 Vendor Advisory
- http://secunia.com/advisories/28800 Vendor Advisory
- http://securityreason.com/securityalert/500
- http://securitytracker.com/id?1015623
Risk Scores
CVSS Score
5.1 / 10
EPSS Score
4.34%
Top 9% most likely to be exploited
Threat Score
21.7 / 100
Data Sources
NVD
EPSS
GitHub