PT-2017-3832 · Graphicsmagick+2 · Graphicsmagick+2

Bob Friesenhahn

·

Publicado

2016-10-08

·

Atualizado

2024-06-15

·

CVE-2016-7997

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions GraphicsMagick versions 1.3.25 and earlier
Description The issue is related to the WPG format reader in GraphicsMagick, which allows remote attackers to cause a denial of service. This can be achieved through vectors related to a ReferenceBlob and a NULL pointer, leading to an assertion failure and crash. The vulnerability is associated with a NULL pointer dereference.
Recommendations For GraphicsMagick versions 1.3.25 and earlier, consider updating to a newer version to mitigate the risk of exploitation. As a temporary workaround, restrict the use of the WPG format reader until a patch is available.

Correção

DoS

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2652
BDU:2019-04038
CVE-2016-7997
DLA-683-1
DSA-3746-1
MGASA-2016-0337
MGASA-2017-0229
OPENSUSE-SU-2016_3060-1
OPENSUSE-SU-2024:10596-1
SUSE-SU-2016:2667-1
SUSE-SU-2016:2724-1
SUSE-SU-2016:2964-1

Produtos afetados

Alt Linux
Graphicsmagick
Suse