CVE-2016-10068: Input Validation
A vulnerability was found in ImageMagick in the MSL interpreter. A maliciously crafted file could cause the application to crash.
Upstream bug:
https://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=30797
References:
http://seclists.org/oss-sec/2016/q4/758 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=845241
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/56d6e20de489113617cbbddaf41e92600a34db22
Other sources
The MSL interpreter in ImageMagick before 6.9.6-4 allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted XML file.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10068?
CVE-2016-10068 has a high severity rating as it can cause the application to crash when processing a specially crafted file.
How do I fix CVE-2016-10068?
To fix CVE-2016-10068, update ImageMagick to version 6.9.6 or later, or apply the appropriate patches provided by your distribution.
What software versions are affected by CVE-2016-10068?
CVE-2016-10068 affects ImageMagick versions up to 6.9.6-3, including specific versions in Red Hat, Debian, and openSUSE environments.
Can CVE-2016-10068 be exploited remotely?
While CVE-2016-10068 is not categorized as a remote code execution vulnerability, a malicious file could lead to application crashes if processed.
What types of applications are impacted by CVE-2016-10068?
Applications utilizing ImageMagick for image processing are impacted by CVE-2016-10068 and may be vulnerable to crashes when processing manipulated files.