CVE-2016-10064: Buffer Overflow
A buffer overflow vulnerability was found in ImageMagick in tiff.c file. A maliciously crafted file could cause the application to crash or possibly have other unspecified impact.
References:
http://seclists.org/oss-sec/2016/q4/758 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=845202
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/f8877abac8e568b2f339cca70c2c3c1b6eaec288
Other sources
Buffer overflow in coders/tiff.c in ImageMagick before 6.9.5-1 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10064?
CVE-2016-10064 has a high severity due to the potential for a buffer overflow leading to application crashes or unspecified impacts.
How do I fix CVE-2016-10064?
To fix CVE-2016-10064, update ImageMagick to version 6.9.5 or higher.
Which versions of ImageMagick are affected by CVE-2016-10064?
CVE-2016-10064 affects ImageMagick versions prior to 6.9.5.
What type of vulnerability is CVE-2016-10064?
CVE-2016-10064 is a buffer overflow vulnerability that can be exploited through maliciously crafted files.
Can CVE-2016-10064 lead to data loss?
Yes, CVE-2016-10064 could potentially lead to data loss by causing the application to crash.