PT-2017-8702 · Imagemagick+5 · Imagemagick+5

Publicado

2016-06-16

·

Atualizado

2018-11-16

·

CVE-2016-5240

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GraphicsMagick versions prior to 1.3.24 ImageMagick (affected versions not specified)
Description The issue allows remote attackers to cause a denial of service, specifically an infinite loop, by converting a circularly defined SVG file. This is due to a problem in the DrawDashPolygon function in GraphicsMagick and the SVG renderer in ImageMagick.
Recommendations For GraphicsMagick versions prior to 1.3.24, update to version 1.3.24 or later to resolve the issue. For ImageMagick, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2652
CESA-2016_1237
CVE-2016-5240
DLA-547-1
DSA-3746-1
MGASA-2016-0252
OPENSUSE-SU-2016_1724-1
OPENSUSE-SU-2016_2073-1
RHSA-2016:1237
RHSA-2016_1237
SUSE-SU-2016:1783-1

Produtos afetados

Alt Linux
Centos
Graphicsmagick
Imagemagick
Red Hat
Suse