PT-2017-1554 · Imagemagick+1 · Imagemagick+1
Donghai Zhu
·
Published
2016-09-23
·
Updated
2020-11-16
·
CVE-2016-10053
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
ImageMagick versions prior to 6.9.5-8
Description
The issue is related to the WriteTIFFImage function in coders/tiff.c, which allows remote attackers to cause a denial of service via a crafted file, resulting in a divide-by-zero error and application crash.
Recommendations
For versions prior to 6.9.5-8, update to version 6.9.5-8 or later to resolve the issue. As a temporary workaround, consider restricting the use of the WriteTIFFImage function until a patch is applied. Avoid processing untrusted or specially crafted TIFF files with the affected ImageMagick versions to minimize the risk of exploitation.
Fix
DoS
Divide By Zero
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Imagemagick