PT-2017-8702 · Imagemagick+5 · Imagemagick+5

Published

2016-06-16

·

Updated

2018-11-16

·

CVE-2016-5240

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GraphicsMagick versions prior to 1.3.24 ImageMagick (affected versions not specified)
Description The issue allows remote attackers to cause a denial of service, specifically an infinite loop, by converting a circularly defined SVG file. This is due to a problem in the DrawDashPolygon function in GraphicsMagick and the SVG renderer in ImageMagick.
Recommendations For GraphicsMagick versions prior to 1.3.24, update to version 1.3.24 or later to resolve the issue. For ImageMagick, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2652
CESA-2016_1237
CVE-2016-5240
DLA-547-1
DSA-3746-1
MGASA-2016-0252
OPENSUSE-SU-2016_1724-1
OPENSUSE-SU-2016_2073-1
RHSA-2016:1237
RHSA-2016_1237
SUSE-SU-2016:1783-1

Affected Products

Alt Linux
Centos
Graphicsmagick
Imagemagick
Red Hat
Suse