PT-2015-3278 · Imagemagick+5 · Imagemagick+5

Moshe Kaplan

+1

·

Published

2015-12-31

·

Updated

2018-05-18

·

CVE-2015-8895

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ImageMagick versions 6.9.1-3 and later
Description The issue is caused by an integer overflow in the ImageMagick console graphic editor. This can be exploited by a remote attacker to cause a denial of service (application crash) by providing large input data. The vulnerability is triggered by a crafted length value that causes a buffer overflow in the coders/icon.c file.
Recommendations For ImageMagick versions 6.9.1-3 and later, consider restricting the input data size to prevent large inputs from causing the application to crash. As a temporary workaround, restrict access to the coders/icon.c file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1580
BDU:2017-00620
CESA-2016_1237
CVE-2015-8895
DLA-353-1
OPENSUSE-SU-2016_1748-1
OPENSUSE-SU-2016_1833-1
RHSA-2016:1237
RHSA-2016_1237
SUSE-SU-2016:1784-1
USN-3131-1

Affected Products

Alt Linux
Centos
Imagemagick
Red Hat
Suse
Ubuntu