CVE-2016-2318: Null Pointer Dereference
Published Feb 3, 2017
·Updated
GraphicsMagick 1.3.23 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted SVG file, related to the (1) DrawImage function in magick/render.c, (2) SVGStartElement function in coders/svg.c, and (3) TraceArcPath function in magick/render.c.
Affected Software
7 affected components
GraphicsMagick Graphicsmagick=1.3.23
Debian Debian Linux=8.0
SUSE Linux Enterprise Debuginfo=11-sp4
SUSE Studio onsite=1.3
openSUSE Leap=42.1
openSUSE openSUSE=13.2
SUSE Linux Enterprise Software Development Kit=11-sp4
Event History
Feb 3, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-2318?
CVE-2016-2318 has been classified as a denial of service vulnerability that can lead to application crashes.
2
How do I fix CVE-2016-2318?
To fix CVE-2016-2318, update GraphicsMagick to version 1.3.24 or later.
3
Which versions of GraphicsMagick are affected by CVE-2016-2318?
GraphicsMagick version 1.3.23 is affected by CVE-2016-2318.
4
Can CVE-2016-2318 be exploited remotely?
Yes, CVE-2016-2318 can be exploited remotely via a crafted SVG file.
5
What platforms are impacted by CVE-2016-2318?
CVE-2016-2318 affects systems running GraphicsMagick 1.3.23 and various versions of Linux distributions including Debian and openSUSE.