The SGI coder in ImageMagick before 7.0.2-10 allows remote attackers to cause a denial of service (out-of-bounds read) via a large row value in an sgi file.
References
Link | Resource |
---|---|
https://github.com/ImageMagick/ImageMagick/commit/8f8959033e4e59418d6506b345829af1f7a71127 | Issue Tracking Patch Third Party Advisory |
https://github.com/ImageMagick/ImageMagick/commit/7afcf9f71043df15508e46f079387bd4689a738d | Issue Tracking Patch Third Party Advisory |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=836776 | Issue Tracking Third Party Advisory |
http://www.openwall.com/lists/oss-security/2016/09/26/8 | Mailing List Patch Third Party Advisory |
http://www.securityfocus.com/bid/93181 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-01-18 09:59
Updated : 2021-04-28 10:55
NVD link : CVE-2016-7101
Mitre link : CVE-2016-7101
JSON object : View
CWE
CWE-125
Out-of-bounds Read
Products Affected
imagemagick
- imagemagick