CVE-2016-7448: High severity GraphicsMagick Graphicsmagick vulnerability
Published Feb 6, 2017
·Updated
The Utah RLE reader in GraphicsMagick before 1.3.25 allows remote attackers to cause a denial of service (CPU consumption or large memory allocations) via vectors involving the header information and the file size.
Affected Software
4 affected components
GraphicsMagick Graphicsmagick<=1.3.24
Debian Debian Linux=8.0
openSUSE Leap=42.1
openSUSE openSUSE=13.2
Event History
Feb 6, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-7448?
CVE-2016-7448 is classified as a denial-of-service vulnerability with a moderate severity level.
2
How do I fix CVE-2016-7448?
To fix CVE-2016-7448, you should upgrade GraphicsMagick to version 1.3.25 or newer.
3
Which versions of GraphicsMagick are affected by CVE-2016-7448?
GraphicsMagick versions prior to 1.3.25 are affected by CVE-2016-7448.
4
Can CVE-2016-7448 be exploited remotely?
Yes, CVE-2016-7448 can be exploited remotely to cause denial of service.
5
What type of impact does CVE-2016-7448 have?
CVE-2016-7448 can lead to high CPU consumption or large memory allocations.