CVE-2016-10051: Use After Free
A use-after-free vulnerability was found in ImageMagick. A maliciously crafted file could cause the application to crash or possibly have other impact.
Upstream bug:
https://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=30245
References:
http://seclists.org/oss-sec/2016/q4/758
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/ecc03a2518c2b7dd375fde3a040fdae0bdf6a521
Other sources
Use-after-free vulnerability in the ReadPWPImage function in coders/pwp.c in ImageMagick 6.9.5-5 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10051?
CVE-2016-10051 is considered a medium severity vulnerability due to its potential to cause application crashes.
How do I fix CVE-2016-10051?
To fix CVE-2016-10051, upgrade ImageMagick to version 6.9.5-6 or later.
What impact can CVE-2016-10051 have on my system?
CVE-2016-10051 can lead to application crashes or potentially allow for further exploitation if a maliciously crafted file is processed.
Which versions of ImageMagick are affected by CVE-2016-10051?
CVE-2016-10051 affects ImageMagick versions up to and including 6.9.5.
Is CVE-2016-10051 a remote code execution vulnerability?
CVE-2016-10051 is not classified as a remote code execution vulnerability but poses risks of application crashes.