CVE-2016-7906: Use After Free
Published Jan 18, 2017
·Updated
magick/attribute.c in ImageMagick 7.0.3-2 allows remote attackers to cause a denial of service (use-after-free) via a crafted file.
Affected Software
2 affected components
ImageMagick ImageMagick=7.0.3-2
Debian Debian Linux=8.0
Remediation
Patch Available
Patch Available
Patch Available
Event History
Jan 18, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-7906?
The severity of CVE-2016-7906 is classified as high due to its potential for denial of service through a use-after-free vulnerability.
2
How do I fix CVE-2016-7906?
To fix CVE-2016-7906, update ImageMagick to version 7.0.3-3 or later.
3
Which versions of ImageMagick are affected by CVE-2016-7906?
CVE-2016-7906 affects ImageMagick version 7.0.3-2.
4
Can CVE-2016-7906 be exploited remotely?
Yes, CVE-2016-7906 can be exploited remotely through crafted files.
5
What type of attack does CVE-2016-7906 enable?
CVE-2016-7906 enables denial of service attacks due to a use-after-free condition.