First published: Fri Feb 03 2017(Updated: )
GraphicsMagick 1.3.23 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted SVG file, related to the (1) DrawImage function in magick/render.c, (2) SVGStartElement function in coders/svg.c, and (3) TraceArcPath function in magick/render.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GraphicsMagick | =1.3.23 | |
Debian GNU/Linux | =8.0 | |
SUSE Linux Enterprise Debuginfo | =11-sp4 | |
SUSE Studio Onsite | =1.3 | |
openSUSE | =42.1 | |
openSUSE | =13.2 | |
SUSE Linux Enterprise Software Development Kit | =11-sp4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2318 has been classified as a denial of service vulnerability that can lead to application crashes.
To fix CVE-2016-2318, update GraphicsMagick to version 1.3.24 or later.
GraphicsMagick version 1.3.23 is affected by CVE-2016-2318.
Yes, CVE-2016-2318 can be exploited remotely via a crafted SVG file.
CVE-2016-2318 affects systems running GraphicsMagick 1.3.23 and various versions of Linux distributions including Debian and openSUSE.