CVE-2016-7997: Null Pointer Dereference
Published Jan 18, 2017
·Updated
The WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (assertion failure and crash) via vectors related to a ReferenceBlob and a NULL pointer.
Affected Software
1 affected component
GraphicsMagick Graphicsmagick<=1.3.25
Remediation
Patch Available
Event History
Jan 18, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-7997?
CVE-2016-7997 is categorized as a denial of service vulnerability.
2
How does CVE-2016-7997 affect GraphicsMagick?
CVE-2016-7997 allows remote attackers to cause GraphicsMagick to crash due to assertion failures.
3
Which versions of GraphicsMagick are affected by CVE-2016-7997?
CVE-2016-7997 affects GraphicsMagick versions prior to 1.3.26.
4
What types of attacks can exploit CVE-2016-7997?
CVE-2016-7997 can be exploited via crafted WPG format files that trigger NULL pointer dereference.
5
Is there a fix for CVE-2016-7997?
To mitigate CVE-2016-7997, upgrading to GraphicsMagick version 1.3.26 or later is recommended.