CVE-2016-6520: Buffer Overflow
Published Dec 13, 2016
·Updated
Buffer overflow in MagickCore/enhance.c in ImageMagick before 7.0.2-7 allows remote attackers to have unspecified impact via vectors related to pixel cache morphology.
Affected Software
1 affected component
ImageMagick>=7.0.0-0<7.0.2-7
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 13, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6520?
CVE-2016-6520 is classified as a high severity vulnerability due to its potential for remote exploitation.
2
How do I fix CVE-2016-6520?
To fix CVE-2016-6520, upgrade ImageMagick to version 7.0.2-7 or later.
3
What types of attacks can exploit CVE-2016-6520?
CVE-2016-6520 can be exploited by remote attackers to cause a buffer overflow that may lead to arbitrary code execution.
4
Which versions of ImageMagick are affected by CVE-2016-6520?
Versions of ImageMagick prior to 7.0.2-7 are affected by CVE-2016-6520.
5
What components of ImageMagick are involved in CVE-2016-6520?
CVE-2016-6520 involves the MagickCore/enhance.c component of ImageMagick.