CVE-2016-7996: Buffer Overflow
Published Jan 18, 2017
·Updated
Heap-based buffer overflow in the WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to have unspecified impact via a colormap with a large number of entries.
Affected Software
1 affected component
GraphicsMagick Graphicsmagick<=1.3.25
Remediation
Patch Available
Event History
Jan 18, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-7996?
CVE-2016-7996 is classified as a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary code.
2
How do I fix CVE-2016-7996?
To fix CVE-2016-7996, update GraphicsMagick to version 1.3.26 or later.
3
What does CVE-2016-7996 affect?
CVE-2016-7996 affects GraphicsMagick versions 1.3.25 and earlier.
4
What type of vulnerability is CVE-2016-7996?
CVE-2016-7996 is a heap-based buffer overflow vulnerability.
5
Who can be impacted by CVE-2016-7996?
Remote attackers can be impacted by CVE-2016-7996 if they exploit the vulnerability through specially crafted colormaps.