CVE-2007-4987
Description
ImageMagick off-by-one in ReadBlobString allows arbitrary code execution via crafted image file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
ImageMagick off-by-one in ReadBlobString allows arbitrary code execution via crafted image file.
Vulnerability
An off-by-one error exists in the ReadBlobString function in blob.c in ImageMagick before version 6.3.5-9. When processing a specially crafted image file, the function writes a '\0' character to an out-of-bounds address, leading to memory corruption. The vulnerability is context-dependent and can be triggered by any image file that reaches this code path [1].
Exploitation
An attacker needs to supply a malicious image file that is processed by ImageMagick by a user or automated system. No additional authentication or network position is required other than delivering the file (e.g., via email attachment, website upload, or automated batch processing). When the file is loaded, the ReadBlobString function copies a string with an off-by-one error, writing a null byte beyond the allocated buffer boundary [4].
Impact
Successful exploitation allows a remote attacker to execute arbitrary code with the privileges of the user running ImageMagick. This can result in complete compromise of confidentiality, integrity, and availability of the affected system [4].
Mitigation
The issue is fixed in ImageMagick version 6.3.5-9. Users should update to this version or later. Ubuntu released an update (USN-523-1) on 3 October 2007 addressing this and related vulnerabilities [4]. No known workarounds are available; applying the patch is the only effective mitigation.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
59cpe:2.3:a:imagemagick:imagemagick:5.3.3:*:*:*:*:*:*:*+ 57 more
- cpe:2.3:a:imagemagick:imagemagick:5.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:5.3.8:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:5.4.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:5.4.3:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:5.4.4.5:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:5.4.7:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:5.4.8:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:5.4.8.2_1.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:5.5.3_.2_1.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:5.5.4:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:5.5.6:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:5.5.6.0_20030409:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:5.5.7:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:5.5.7.15:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.0:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.0.2.5:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.0.4.4:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.0.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.1:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.1.8:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.2:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.2.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.2.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.2.3.4:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.2.4.3:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.2.4.5:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.2.5:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.2.6:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.2.7:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.2.8:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.2.9:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.2.9.2:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.3.3_3:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.3.3_5:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.3.3_6:*:*:*:*:*:*:*
- cpe:2.3:a:imagemagick:imagemagick:6.3.4:*:*:*:*:*:*:*
- (no CPE)range: <6.3.5-9
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
22- www.securityfocus.com/bid/25766nvdExploitPatch
- bugs.gentoo.org/show_bug.cginvd
- labs.idefense.com/intelligence/vulnerabilities/display.phpnvd
- secunia.com/advisories/26926nvd
- secunia.com/advisories/27048nvd
- secunia.com/advisories/27309nvd
- secunia.com/advisories/27364nvd
- secunia.com/advisories/27439nvd
- secunia.com/advisories/28721nvd
- secunia.com/advisories/36260nvd
- security.gentoo.org/glsa/glsa-200710-27.xmlnvd
- studio.imagemagick.org/pipermail/magick-announce/2007-September/000037.htmlnvd
- www.debian.org/security/2009/dsa-1858nvd
- www.imagemagick.org/script/changelog.phpnvd
- www.mandriva.com/en/security/advisoriesnvd
- www.novell.com/linux/security/advisories/2007_23_sr.htmlnvd
- www.securityfocus.com/archive/1/483572/100/0/threadednvd
- www.securitytracker.com/idnvd
- www.ubuntu.com/usn/usn-523-1nvd
- www.vupen.com/english/advisories/2007/3245nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/36739nvd
- issues.rpath.com/browse/RPL-1743nvd
News mentions
0No linked articles in our index yet.