CVE-2016-10145: Critical severity imagemagick vulnerability
Published Jan 15, 2017
·Updated
Off-by-one error in coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via vectors related to a string copy.
Affected Software
3 affected componentsFixes available
debian/imagemagick
8:6.9.11.60+dfsg-1.3+deb11u48:6.9.11.60+dfsg-1.3+deb11u38:6.9.11.60+dfsg-1.6+deb12u28:6.9.11.60+dfsg-1.6+deb12u18:6.9.13.12+dfsg1-18:7.1.1.39+dfsg1-2
ImageMagick<6.9.7-1
ImageMagick
Remediation
Patch Available
Patch Available
Patch Available
Event History
Jan 15, 2017
Data Sourced
02:12 PM
SeverityAffected Software
Mar 24, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10145?
CVE-2016-10145 has a medium severity rating due to its potential impact on system security.
2
How do I fix CVE-2016-10145?
To fix CVE-2016-10145, update ImageMagick to version 6.9.11.60 or higher.
3
Which versions of ImageMagick are affected by CVE-2016-10145?
CVE-2016-10145 affects all versions of ImageMagick prior to 6.9.11.60.
4
Can CVE-2016-10145 be exploited remotely?
Yes, CVE-2016-10145 can be exploited remotely through crafted image files.
5
What kind of attack does CVE-2016-10145 facilitate?
CVE-2016-10145 facilitates potential denial of service attacks or arbitrary code execution.