CVE-2016-10050: Buffer Overflow
A heap-buffer overflow vulnerability was found in ImageMagick. A maliciously crafted RLE file could cause the application to crash or possibly have other impact.
References:
http://seclists.org/oss-sec/2016/q4/758 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=833744
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/73fb0aac5b958521e1511e179ecc0ad49f70ebaf
Other sources
Heap-based buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.9.4-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted RLE file.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10050?
CVE-2016-10050 has a high severity due to potential crashes and exploitation through crafted RLE files.
How do I fix CVE-2016-10050?
To fix CVE-2016-10050, update ImageMagick to version 6.9.4-8 or later.
What systems are affected by CVE-2016-10050?
CVE-2016-10050 affects ImageMagick versions prior to 6.9.4-8 on various systems including Red Hat and openSUSE.
What kind of attack can exploit CVE-2016-10050?
An attacker can exploit CVE-2016-10050 by sending a maliciously crafted RLE file to cause a heap-buffer overflow.
What is the impact of CVE-2016-10050?
The impact of CVE-2016-10050 includes application crashes and potential unauthorized access or control.