CVE-2016-2317: Buffer Overflow
Multiple buffer overflows in GraphicsMagick 1.3.23 allow remote attackers to cause a denial of service (crash) via a crafted SVG file, related to the (1) TracePoint function in magick/render.c, (2) GetToken function in magick/utility.c, and (3) GetTransformTokens function in coders/svg.c.
Other sources
Various issues were found in the processing of SVG files in GraphicsMagick:
http://seclists.org/oss-sec/2016/q1/297
Upstream patches are not available yet.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2317?
CVE-2016-2317 is rated as a high severity vulnerability due to the potential for denial of service attacks.
How do I fix CVE-2016-2317?
To fix CVE-2016-2317, upgrade GraphicsMagick to version 1.3.24 or later.
Which versions of GraphicsMagick are affected by CVE-2016-2317?
GraphicsMagick version 1.3.23 is specifically affected by CVE-2016-2317.
What type of vulnerability is CVE-2016-2317?
CVE-2016-2317 is a buffer overflow vulnerability that can result in application crashes.
Can CVE-2016-2317 be exploited remotely?
Yes, CVE-2016-2317 can be exploited remotely using crafted SVG files.