CVE-2016-4564: Buffer Overflow
The DrawImage function in MagickCore/draw.c in ImageMagick before 6.9.4-0 and 7.x before 7.0.1-2 makes an incorrect function call in attempting to locate the next token, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4564?
CVE-2016-4564 has a moderate severity level, as it can lead to denial of service due to a buffer overflow.
How do I fix CVE-2016-4564?
To fix CVE-2016-4564, update ImageMagick to version 6.9.4-0 or later, or 7.0.1-2 or later.
What are the affected versions for CVE-2016-4564?
CVE-2016-4564 affects ImageMagick versions prior to 6.9.4-0 and 7.x prior to 7.0.1-2.
What type of vulnerability is CVE-2016-4564?
CVE-2016-4564 is a denial of service vulnerability caused by an incorrect function call in ImageMagick.
Can CVE-2016-4564 be exploited remotely?
Yes, CVE-2016-4564 can be exploited remotely by attackers to cause application crashes.