CVE-2016-7447: Buffer Overflow
Published Feb 6, 2017
·Updated
Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspecified impact via unknown vectors.
Affected Software
4 affected components
GraphicsMagick Graphicsmagick<=1.3.24
Debian Debian Linux=8.0
openSUSE Leap=42.1
openSUSE openSUSE=13.2
Event History
Feb 6, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-7447?
CVE-2016-7447 is categorized as a high severity vulnerability due to its potential for remote exploitation through a heap-based buffer overflow.
2
How do I fix CVE-2016-7447?
To fix CVE-2016-7447, upgrade GraphicsMagick to version 1.3.25 or later, or apply the relevant patches if available.
3
Which versions of GraphicsMagick are affected by CVE-2016-7447?
CVE-2016-7447 affects GraphicsMagick versions prior to 1.3.25.
4
Are Debian distributions vulnerable to CVE-2016-7447?
Yes, Debian Linux 8.0 is vulnerable to CVE-2016-7447 if using an affected version of GraphicsMagick.
5
Can CVE-2016-7447 be exploited by remote attackers?
Yes, CVE-2016-7447 can be exploited by remote attackers through unknown vectors, allowing for unspecified impacts.