PT-2017-1556 · Imagemagick+1 · Imagemagick+1

Myliniem

·

Publicado

2016-08-25

·

Atualizado

2020-11-16

·

CVE-2016-10051

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ImageMagick version 6.9.5-5
Description The issue is related to a use-after-free vulnerability in the ReadPWPImage function in coders/pwp.c. This vulnerability can be exploited by remote attackers using a crafted file, potentially causing a denial of service (application crash) or having other unspecified impact.
Recommendations For ImageMagick version 6.9.5-5, consider disabling the ReadPWPImage function in coders/pwp.c as a temporary workaround until a patch is available. Restrict access to crafted files that could exploit this vulnerability to minimize the risk of application crash or other unspecified impact. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-00701
CVE-2016-10051
DLA-731-1
DSA-3652-1
MGASA-2018-0229
SUSE-SU-2017:0518-1
SUSE-SU-2017:0529-1
SUSE-SU-2017:0586-1

Produtos afetados

Imagemagick
Suse