PT-2017-1556 · Imagemagick+1 · Imagemagick+1
Myliniem
·
Published
2016-08-25
·
Updated
2020-11-16
·
CVE-2016-10051
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ImageMagick version 6.9.5-5
Description
The issue is related to a use-after-free vulnerability in the ReadPWPImage function in coders/pwp.c. This vulnerability can be exploited by remote attackers using a crafted file, potentially causing a denial of service (application crash) or having other unspecified impact.
Recommendations
For ImageMagick version 6.9.5-5, consider disabling the ReadPWPImage function in coders/pwp.c as a temporary workaround until a patch is available. Restrict access to crafted files that could exploit this vulnerability to minimize the risk of application crash or other unspecified impact. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Imagemagick
Suse