PT-2017-1554 · Imagemagick+1 · Imagemagick+1

Donghai Zhu

·

Published

2016-09-23

·

Updated

2020-11-16

·

CVE-2016-10053

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 6.9.5-8
Description The issue is related to the WriteTIFFImage function in coders/tiff.c, which allows remote attackers to cause a denial of service via a crafted file, resulting in a divide-by-zero error and application crash.
Recommendations For versions prior to 6.9.5-8, update to version 6.9.5-8 or later to resolve the issue. As a temporary workaround, consider restricting the use of the WriteTIFFImage function until a patch is applied. Avoid processing untrusted or specially crafted TIFF files with the affected ImageMagick versions to minimize the risk of exploitation.

Fix

DoS

Divide By Zero

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2089
BDU:2017-00699
CVE-2016-10053
DSA-3675-1
MGASA-2018-0229

Affected Products

Alt Linux
Imagemagick