First published: Wed Oct 07 2015(Updated: )
An integer truncation flaw leading to a heap-based buffer overflow was found in ImageMagick in pict.c. Detailed stacktrace with reproducer can be found here: <a href="https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1448803">https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1448803</a> Upstream patch for the pict.c problem is a subsection (the pict.c part) of the following commit: <a href="https://github.com/ImageMagick/ImageMagick/commit/0f6fc2d5bf8f500820c3dbcf0d23ee14f2d9f734">https://github.com/ImageMagick/ImageMagick/commit/0f6fc2d5bf8f500820c3dbcf0d23ee14f2d9f734</a> CVE request: <a href="http://seclists.org/oss-sec/2015/q4/45">http://seclists.org/oss-sec/2015/q4/45</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick | <6.9.4-0 | |
ImageMagick | >=7.0.0-0<7.0.5-0 | |
Oracle Linux | =6 | |
Oracle Linux | =7 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Desktop | =7.0 | |
Red Hat Enterprise Linux Server EUS | =7.2 | |
Red Hat Enterprise Linux Server EUS | =7.3 | |
Red Hat Enterprise Linux Server EUS | =7.4 | |
Red Hat Enterprise Linux Server EUS | =7.5 | |
Red Hat Enterprise Linux Server EUS | =7.6 | |
Red Hat Enterprise Linux Server EUS | =7.7 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Server | =7.0 | |
Red Hat Enterprise Linux Server | =7.2 | |
Red Hat Enterprise Linux Server | =7.3 | |
Red Hat Enterprise Linux Server | =7.4 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Server | =7.7 | |
Red Hat Enterprise Linux Server | =7.2 | |
Red Hat Enterprise Linux Server | =7.3 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Server | =7.7 | |
Red Hat Enterprise Linux Workstation | =6.0 | |
Red Hat Enterprise Linux Workstation | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8896 has a high severity rating due to the potential for a heap-based buffer overflow.
To fix CVE-2015-8896, upgrade ImageMagick to version 6.9.4-0 or later, or to a version between 7.0.0-0 and 7.0.5-0.
CVE-2015-8896 affects various versions of ImageMagick and several distributions including Oracle Linux and Red Hat Enterprise Linux.
CVE-2015-8896 is an integer truncation flaw that leads to a heap-based buffer overflow.
Yes, CVE-2015-8896 can be exploited by attackers to execute arbitrary code or cause a denial of service.