PT-2017-1556 · Imagemagick+1 · Imagemagick+1

Myliniem

·

Published

2016-08-25

·

Updated

2020-11-16

·

CVE-2016-10051

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ImageMagick version 6.9.5-5
Description The issue is related to a use-after-free vulnerability in the ReadPWPImage function in coders/pwp.c. This vulnerability can be exploited by remote attackers using a crafted file, potentially causing a denial of service (application crash) or having other unspecified impact.
Recommendations For ImageMagick version 6.9.5-5, consider disabling the ReadPWPImage function in coders/pwp.c as a temporary workaround until a patch is available. Restrict access to crafted files that could exploit this vulnerability to minimize the risk of application crash or other unspecified impact. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-00701
CVE-2016-10051
DLA-731-1
DSA-3652-1
MGASA-2018-0229
SUSE-SU-2017:0518-1
SUSE-SU-2017:0529-1
SUSE-SU-2017:0586-1

Affected Products

Imagemagick
Suse