Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-4988

21
FAUCET Score

CVE-2007-4988 is a critical vulnerability in ImageMagick, affecting versions prior to 6.3.5-9, including those in Canonical Ubuntu Linux. It stems from a sign extension error in the ReadDIBImage function, leading to an integer overflow and subsequent heap-based buffer overflow when processing crafted image files with malicious width values. With a CVSS score of 7.8 (High), this vulnerability allows context-dependent attackers to execute arbitrary code with user interaction (UI:R), potentially leading to complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). Despite its severity, there is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 6.3.5-9CPE matchmatch criteria
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
6.06CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*
6.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:*
7.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:7.04:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
3.09%
Probability of exploitation in next 30 days
EPSS Percentile
86.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0309 is in the 87th percentile among its peer group of 11,621 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: ImageMagick-0:5.5.6-28
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: ImageMagick-0:6.0.7.1-17.el4_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: ImageMagick-0:6.2.8.0-4.el5_1.1
View patch

Vendor Advisories (1)

redhatCVE-2007-4988Moderate

Integer overflow in ImageMagick's DIB coder

Sep 19, 2007

References

bugs.gentoo.org / show_bug.cgi
Issue Tracking
labs.idefense.com / intelligence/vulnerabilities/display.php
Broken Link
secunia.com / advisories/26926
Broken Link
secunia.com / advisories/27048
Broken Link
secunia.com / advisories/27309
Broken Link
secunia.com / advisories/27364
Broken Link
secunia.com / advisories/27439
Broken Link
secunia.com / advisories/28721
Broken Link
secunia.com / advisories/29786
Broken Link
secunia.com / advisories/36260
Broken Link
security.gentoo.org / glsa/glsa-200710-27.xml
Third Party Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/36737
Third Party AdvisoryVDB Entry
issues.rpath.com / browse/RPL-1743
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9656
Broken Link
studio.imagemagick.org / pipermail/magick-announce/2007-September/000037.html
Broken Link
debian.org / security/2009/dsa-1858
Mailing ListThird Party Advisory
imagemagick.org / script/changelog.php
Release Notes
mandriva.com / en/security/advisories
Broken Link
novell.com / linux/security/advisories/2007_23_sr.html
Broken Link
redhat.com / support/errata/RHSA-2008-0145.html
Broken Link
securityfocus.com / archive/1/483572/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / bid/25765
Broken LinkExploitPatchThird Party AdvisoryVDB Entry
securitytracker.com / id
Broken LinkThird Party AdvisoryVDB Entry
ubuntu.com / usn/usn-523-1
Third Party Advisory
vupen.com / english/advisories/2007/3245
Broken Link