CVE-2016-10144: Critical severity imagemagick vulnerability
Published Jan 15, 2017
·Updated
coders/ipl.c in ImageMagick allows remote attackers to have unspecific impact by leveraging a missing malloc check.
Affected Software
2 affected components
ImageMagick<6.9.7-1
ImageMagick
Remediation
Patch Available
Patch Available
Patch Available
Event History
Jan 15, 2017
Data Sourced
02:15 PM
SeverityAffected Software
Mar 24, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10144?
The severity of CVE-2016-10144 is considered to be high due to potential remote exploitation risks.
2
How do I fix CVE-2016-10144?
To fix CVE-2016-10144, update ImageMagick to a version later than 6.9.7-1 that addresses the vulnerability.
3
Who is affected by CVE-2016-10144?
CVE-2016-10144 affects all versions of ImageMagick prior to 6.9.7-1.
4
What type of attack can exploit CVE-2016-10144?
CVE-2016-10144 can potentially be exploited by remote attackers to cause unspecified impacts.
5
What component of ImageMagick is impacted by CVE-2016-10144?
CVE-2016-10144 impacts the coders/ipl.c component of ImageMagick.