CVE-2006-2440
Estado: ModificadaAlta (7.5)—
Heap-based buffer overflow in the libMagick component of ImageMagick 6.0.6.2 might allow attackers to execute arbitrary code via an image index array that triggers the overflow during filename glob expansion by the ExpandFilenames function.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.86%
- Percentil entre todas las CVEs puntuadas: 86
- Fecha de la puntuación: 9/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345595
- http://secunia.com/advisories/21719
- http://secunia.com/advisories/24186
- http://secunia.com/advisories/24284
- http://www.debian.org/security/2006/dsa-1168
- http://www.redhat.com/support/errata/RHSA-2007-0015.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9481
- ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345595
- http://secunia.com/advisories/21719
- http://secunia.com/advisories/24186
- http://secunia.com/advisories/24284
- http://www.debian.org/security/2006/dsa-1168
- http://www.redhat.com/support/errata/RHSA-2007-0015.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9481
JSON original (NVD)
Mostrar
{
"id": "CVE-2006-2440",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": true,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-05-18T10:02:00.000",
"references": [
{
"url": "ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc",
"source": "cve@mitre.org"
},
{
"url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345595",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/21719",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/24186",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/24284",
"source": "cve@mitre.org"
},
{
"url": "http://www.debian.org/security/2006/dsa-1168",
"source": "cve@mitre.org"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2007-0015.html",
"source": "cve@mitre.org"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9481",
"source": "cve@mitre.org"
},
{
"url": "ftp://patches.sgi.com/support/free/security/advisories/20070201-01-P.asc",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345595",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/21719",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/24186",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/24284",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2006/dsa-1168",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.redhat.com/support/errata/RHSA-2007-0015.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9481",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Heap-based buffer overflow in the libMagick component of ImageMagick 6.0.6.2 might allow attackers to execute arbitrary code via an image index array that triggers the overflow during filename glob expansion by the ExpandFilenames function."
}
],
"lastModified": "2026-06-16T22:25:00.880",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:imagemagick:imagemagick:6.0.6.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F91C63C5-765B-4511-B6CF-CA09433DE051"
},
{
"criteria": "cpe:2.3:a:imagemagick:imagemagick:6.2.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CDA9ACBD-6065-4340-B987-560BE5A54FE1"
}
],
"operator": "OR"
}
]
}
],
"vendorComments": [
{
"comment": "Red Hat is aware of this issue and is tracking it via the following bug:\nhttps://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=192278\n\nThe Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw. More information regarding issue severity can be found here:\nhttp://www.redhat.com/security/updates/classification/\n\nThis issue does not affect Red Hat Enterprise Linux 2.1 or 3.\n",
"lastModified": "2006-09-19T00:00:00",
"organization": "Red Hat"
}
],
"sourceIdentifier": "cve@mitre.org"
}