RULE(RULE ID:705812)

Rule General Information
Release Date: 2014-12-18
Rule Name: Imagemagick GIF Comment Processing Off-by-one Buffer Overflow Vulnerability (CVE-2013-4298)
Severity:
CVE ID:
Rule Protection Details
Description: The ReadGIFImage function in coders/gif.c in ImageMagick before 6.7.8-8 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted comment in a GIF image.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks include arbitrary code execution and denial of service.
Affected OS: Windows, Linux
Reference: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=721273
http://www.debian.org/security/2013/dsa-2750
http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=23921
Solutions
More advisories have been published on the website, please visit for more suggestions:
http://www.imagemagick.org/script/download.php