First published: Fri Mar 10 2017(Updated: )
Memory leak in the IsOptionMember function in MagickCore/option.c in ImageMagick before 6.9.2-2, as used in ODR-PadEnc and other products, allows attackers to trigger memory consumption.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/imagemagick | <=8:6.6.0.4-3<=8:6.7.7.10-5 | 8:6.9.2.10+dfsg-1 8:6.9.6.2+dfsg-2 8:6.8.9.9-5+deb8u8 |
ImageMagick | <=6.9.2-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-10252 is classified as moderate due to its potential for memory consumption attacks.
To fix CVE-2016-10252, update ImageMagick to version 6.9.2-2 or later.
CVE-2016-10252 affects various versions of ImageMagick prior to 6.9.2-2, including multiple Debian packages.
CVE-2016-10252 is a memory leak vulnerability in the IsOptionMember function of ImageMagick.
Yes, CVE-2016-10252 can potentially be exploited remotely, allowing attackers to trigger memory consumption.