PT-2017-9189 · Graphicsmagick+1 · Graphicsmagick+1

Agostino Sarubbo

·

Published

2016-09-28

·

Updated

2019-04-12

·

CVE-2016-7449

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GraphicsMagick version 1.3.24
Description The issue allows remote attackers to cause a denial of service, specifically an out-of-bounds heap read, by providing a file with an "unterminated" string. This is related to the TIFFGetField function in coders/tiff.c.
Recommendations For GraphicsMagick version 1.3.24, consider avoiding the use of the TIFFGetField function until a patch is available. As a temporary workaround, restrict the processing of TIFF files containing potentially "unterminated" strings to minimize the risk of exploitation.

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-7449
DLA-1401-1
DLA-651-1
MGASA-2016-0325
SUSE-SU-2016:2724-1

Affected Products

Graphicsmagick
Suse