First published: Wed Jan 18 2017(Updated: )
MagickCore/profile.c in ImageMagick before 7.0.3-2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick | <6.9.6-0 | |
ImageMagick | >=7.0.0-0<7.0.3-2 | |
Debian Linux | =8.0 | |
<6.9.6-0 | ||
>=7.0.0-0<7.0.3-2 | ||
=8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7799 has been classified as a denial of service vulnerability due to out-of-bounds read.
To fix CVE-2016-7799, upgrade to ImageMagick version 7.0.3-2 or later.
CVE-2016-7799 affects ImageMagick versions earlier than 7.0.3-2 and Debian 8.0.
Yes, CVE-2016-7799 can be exploited by remote attackers using a crafted file.
Systems running vulnerable versions of ImageMagick or Debian 8.0 are susceptible to CVE-2016-7799.