PT-2017-1556 · Imagemagick+1 · Imagemagick+1
Myliniem
·
Publicado
2016-08-25
·
Atualizado
2020-11-16
·
CVE-2016-10051
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ImageMagick version 6.9.5-5
Description
The issue is related to a use-after-free vulnerability in the ReadPWPImage function in coders/pwp.c. This vulnerability can be exploited by remote attackers using a crafted file, potentially causing a denial of service (application crash) or having other unspecified impact.
Recommendations
For ImageMagick version 6.9.5-5, consider disabling the ReadPWPImage function in coders/pwp.c as a temporary workaround until a patch is available. Restrict access to crafted files that could exploit this vulnerability to minimize the risk of application crash or other unspecified impact. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Use After Free
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Imagemagick
Suse