First published: Wed Jan 18 2017(Updated: )
magick/attribute.c in ImageMagick 7.0.3-2 allows remote attackers to cause a denial of service (use-after-free) via a crafted file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick | =7.0.3-2 | |
Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-7906 is classified as high due to its potential for denial of service through a use-after-free vulnerability.
To fix CVE-2016-7906, update ImageMagick to version 7.0.3-3 or later.
CVE-2016-7906 affects ImageMagick version 7.0.3-2.
Yes, CVE-2016-7906 can be exploited remotely through crafted files.
CVE-2016-7906 enables denial of service attacks due to a use-after-free condition.