PT-2017-9189 · Graphicsmagick+1 · Graphicsmagick+1

Agostino Sarubbo

·

Publicado

2016-09-28

·

Atualizado

2019-04-12

·

CVE-2016-7449

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GraphicsMagick version 1.3.24
Description The issue allows remote attackers to cause a denial of service, specifically an out-of-bounds heap read, by providing a file with an "unterminated" string. This is related to the TIFFGetField function in coders/tiff.c.
Recommendations For GraphicsMagick version 1.3.24, consider avoiding the use of the TIFFGetField function until a patch is available. As a temporary workaround, restrict the processing of TIFF files containing potentially "unterminated" strings to minimize the risk of exploitation.

Correção

DoS

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-7449
DLA-1401-1
DLA-651-1
MGASA-2016-0325
SUSE-SU-2016:2724-1

Produtos afetados

Graphicsmagick
Suse