First published: Tue Aug 16 2016(Updated: )
Integer overflow in the BMP coder in ImageMagick before 7.0.2-10 allows remote attackers to cause a denial of service (crash) via crafted height and width values, which triggers an out-of-bounds write.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/imagemagick | <=8:6.7.7.10-4<=8:6.7.7.10-5 | 8:6.8.9.9-5+deb8u4 8:6.9.5.9+dfsg-1 |
ImageMagick | <6.9.10-50 | |
ImageMagick | >=7.0.0-0<7.0.2-10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6823 has a severity rating that indicates it can lead to denial of service attacks through crashes.
To fix CVE-2016-6823, upgrade ImageMagick to version 7.0.2-10 or higher.
CVE-2016-6823 affects ImageMagick versions prior to 7.0.2-10 and several 6.x versions up to 6.9.10-50.
CVE-2016-6823 allows remote attackers to execute a denial of service attack by causing crashes through crafted image dimensions.
Yes, CVE-2016-6823 is specifically related to integer overflow in the BMP coder used in ImageMagick for image processing.