PT-2016-7555 · Imagemagick+2 · Imagemagick+2

Published

2016-12-22

·

Updated

2022-12-14

·

CVE-2016-8707

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ImageMagick (affected versions not specified)
Description An exploitable out of bounds write exists in the handling of compressed TIFF images in ImageMagick's convert utility. A crafted TIFF document can lead to an out of bounds write, which in particular circumstances could be leveraged into remote code execution. The issue can be triggered through any user-controlled TIFF that is handled by this functionality.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2016-8707
DLA-756-1
DSA-3799-1
MGASA-2018-0229
OPENSUSE-SU-2016_3233-1
OPENSUSE-SU-2017_0023-1
SUSE-SU-2016:3256-1
SUSE-SU-2016:3258-1
USN-3222-1

Affected Products

Imagemagick
Suse
Ubuntu