PT-2017-3832 · Graphicsmagick+2 · Graphicsmagick+2
Bob Friesenhahn
·
Publicado
2016-10-08
·
Atualizado
2024-06-15
·
CVE-2016-7997
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
GraphicsMagick versions 1.3.25 and earlier
Description
The issue is related to the WPG format reader in GraphicsMagick, which allows remote attackers to cause a denial of service. This can be achieved through vectors related to a ReferenceBlob and a NULL pointer, leading to an assertion failure and crash. The vulnerability is associated with a NULL pointer dereference.
Recommendations
For GraphicsMagick versions 1.3.25 and earlier, consider updating to a newer version to mitigate the risk of exploitation. As a temporary workaround, restrict the use of the WPG format reader until a patch is available.
Correção
DoS
NULL Pointer Dereference
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Graphicsmagick
Suse