CVE-2016-5688
13.12.2016, 15:59
The WPG parser in ImageMagick before 6.9.4-4 and 7.x before 7.0.1-5, when a memory limit is set, allows remote attackers to have unspecified impact via vectors related to the SetImageExtent return-value check, which trigger (1) a heap-based buffer overflow in the SetPixelIndex function or an invalid write operation in the (2) ScaleCharToQuantum or (3) SetPixelIndex functions.Enginsight
| Vendor | Product | Version |
|---|---|---|
| oracle | solaris | 11.3 |
| imagemagick | imagemagick | 𝑥 ≤ 6.9.4-3 |
| imagemagick | imagemagick | 7.0.1-0 |
| imagemagick | imagemagick | 7.0.1-1 |
| imagemagick | imagemagick | 7.0.1-2 |
| imagemagick | imagemagick | 7.0.1-3 |
| imagemagick | imagemagick | 7.0.1-4 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References