First published: Tue Dec 13 2016(Updated: )
The ReadDCMImage function in DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact via vectors involving the for statement in computing the pixel scaling table.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/imagemagick | 8:6.9.11.60+dfsg-1.3+deb11u3 8:6.9.11.60+dfsg-1.6+deb12u1 8:6.9.13.12+dfsg1-1 | |
Oracle Solaris SPARC | =11.3 | |
ImageMagick | <=6.9.4-4 | |
ImageMagick | =7.0.1-0 | |
ImageMagick | =7.0.1-1 | |
ImageMagick | =7.0.1-2 | |
ImageMagick | =7.0.1-3 | |
ImageMagick | =7.0.1-4 | |
ImageMagick | =7.0.1-5 | |
ImageMagick | =7.0.1-6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5690 has a moderate severity level, allowing remote attackers potential impact through specific pixel scaling modifications.
To fix CVE-2016-5690, upgrade ImageMagick to versions 6.9.4-5 or later, or 7.0.1-7 or later.
ImageMagick versions before 6.9.4-5 and 7.x prior to 7.0.1-7 are affected by CVE-2016-5690.
CVE-2016-5690 may potentially allow for unspecified impact but does not explicitly lead to code execution.
The impact of CVE-2016-5690 on users includes potential manipulation of images that may affect application behavior.