CVE-2016-10069: Input Validation
A vulnerability was found in ImageMagick in mat.c file. A maliciously crafted file could cause the application to crash.
References:
http://seclists.org/oss-sec/2016/q4/758 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=845244
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/8a370f9ab120faf182aa160900ba692ba8e2bcf0
Other sources
coders/mat.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a denial of service (application crash) via a mat file with an invalid number of frames.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10069?
The severity of CVE-2016-10069 is considered moderate due to its potential to cause application crashes.
How do I fix CVE-2016-10069?
To fix CVE-2016-10069, update ImageMagick to version 6.9.4 or later.
What software is affected by CVE-2016-10069?
CVE-2016-10069 affects ImageMagick versions up to 6.9.4 and specific distributions such as Red Hat and openSUSE Leap.
What is the impact of CVE-2016-10069?
The impact of CVE-2016-10069 is that a maliciously crafted file can lead to application crashes and potential denial of service.
Is CVE-2016-10069 related to file handling in ImageMagick?
Yes, CVE-2016-10069 is related to vulnerabilities in handling certain file types within ImageMagick.