PT-2017-1554 · Imagemagick+1 · Imagemagick+1
Donghai Zhu
·
Publicado
2016-09-23
·
Atualizado
2020-11-16
·
CVE-2016-10053
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
ImageMagick versions prior to 6.9.5-8
Description
The issue is related to the WriteTIFFImage function in coders/tiff.c, which allows remote attackers to cause a denial of service via a crafted file, resulting in a divide-by-zero error and application crash.
Recommendations
For versions prior to 6.9.5-8, update to version 6.9.5-8 or later to resolve the issue. As a temporary workaround, consider restricting the use of the WriteTIFFImage function until a patch is applied. Avoid processing untrusted or specially crafted TIFF files with the affected ImageMagick versions to minimize the risk of exploitation.
Correção
DoS
Divide By Zero
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Imagemagick