First published: Tue Dec 13 2016(Updated: )
Integer overflow in MagickCore/profile.c in ImageMagick before 7.0.2-1 allows remote attackers to cause a denial of service (segmentation fault) or possibly execute arbitrary code via vectors involving the offset variable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/imagemagick | 8:6.9.11.60+dfsg-1.3+deb11u3 8:6.9.11.60+dfsg-1.6+deb12u1 8:6.9.13.12+dfsg1-1 | |
ImageMagick ImageMagick | <=7.0.2-0 | |
Oracle Solaris SPARC | =10.0 | |
Oracle Solaris SPARC | =11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5841 is classified as a high severity vulnerability due to its potential to cause denial of service or arbitrary code execution.
To fix CVE-2016-5841, update ImageMagick to version 7.0.2-1 or later.
The potential impacts of CVE-2016-5841 include denial of service through segmentation faults and possible execution of arbitrary code.
CVE-2016-5841 affects all ImageMagick versions prior to 7.0.2-1 and specific versions of Oracle Solaris.
Yes, CVE-2016-5841 can be exploited remotely by attackers to trigger the vulnerability.