First published: Wed Jan 18 2017(Updated: )
Heap-based buffer overflow in the WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to have unspecified impact via a colormap with a large number of entries.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GraphicsMagick | <=1.3.25 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7996 is classified as a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary code.
To fix CVE-2016-7996, update GraphicsMagick to version 1.3.26 or later.
CVE-2016-7996 affects GraphicsMagick versions 1.3.25 and earlier.
CVE-2016-7996 is a heap-based buffer overflow vulnerability.
Remote attackers can be impacted by CVE-2016-7996 if they exploit the vulnerability through specially crafted colormaps.