CVE-2016-7449: High severity GraphicsMagick Graphicsmagick vulnerability
Published Feb 6, 2017
·Updated
The TIFFGetField function in coders/tiff.c in GraphicsMagick 1.3.24 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a file containing an "unterminated" string.
Affected Software
4 affected components
GraphicsMagick Graphicsmagick=1.3.24
Debian Debian Linux=8.0
openSUSE Leap=42.1
openSUSE openSUSE=13.2
Event History
Feb 6, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-7449?
CVE-2016-7449 has a severity rating that indicates it can lead to a denial of service due to an out-of-bounds heap read.
2
How do I fix CVE-2016-7449?
To fix CVE-2016-7449, update GraphicsMagick to version 1.3.25 or later.
3
Which software versions are affected by CVE-2016-7449?
CVE-2016-7449 affects GraphicsMagick version 1.3.24 and certain versions of Debian and openSUSE Linux.
4
Can CVE-2016-7449 be exploited remotely?
Yes, CVE-2016-7449 can be exploited by remote attackers through specially crafted TIFF files.
5
Does CVE-2016-7449 affect only Linux systems?
While CVE-2016-7449 is mentioned in relation to Linux distributions, it primarily affects the GraphicsMagick software, which may run on various platforms.