PT-2016-3279 · Graphicsmagick+2 · Graphicsmagick+2

Bob Friesenhahn

·

Publicado

2016-10-07

·

Atualizado

2024-06-15

·

CVE-2016-7996

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GraphicsMagick versions 1.3.25 and earlier
Description The issue is related to a heap-based buffer overflow in the WPG format reader, which can be exploited by remote attackers using a colormap with a large number of entries. This may allow an attacker to cause unspecified impact, potentially including denial of service or execution of arbitrary code.
Recommendations For GraphicsMagick versions 1.3.25 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2652
BDU:2019-00424
CVE-2016-7996
DLA-683-1
DSA-3746-1
MGASA-2016-0337
MGASA-2017-0229
OPENSUSE-SU-2016_3060-1
OPENSUSE-SU-2024:10596-1
SUSE-SU-2016:2667-1
SUSE-SU-2016:2724-1
SUSE-SU-2016:2964-1
SUSE-SU-2017:3435-1
SUSE-SU-2017_3435-1

Produtos afetados

Alt Linux
Graphicsmagick
Suse