CVE-2016-8677: High severity ImageMagick ImageMagick vulnerability
A memory allocation failure was found in ImageMagick in quantum.c.
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/6e48aa92ff4e6e95424300ecd52a9ea453c19c60
References:
http://seclists.org/oss-sec/2016/q4/66 https://blogs.gentoo.org/ago/2016/10/07/imagemagick-memory-allocate-failure-in-acquirequantumpixels-quantum-c/
Other sources
The AcquireQuantumPixels function in MagickCore/quantum.c in ImageMagick before 7.0.3-1 allows remote attackers to have unspecified impact via a crafted image file, which triggers a memory allocation failure.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8677?
CVE-2016-8677 has been classified as a high severity vulnerability due to its potential to cause denial of service through memory allocation failure.
How do I fix CVE-2016-8677?
To fix CVE-2016-8677, you should upgrade to ImageMagick version 7.0.3.1 or later.
Which systems are affected by CVE-2016-8677?
CVE-2016-8677 affects various systems that use ImageMagick versions prior to 7.0.3.1 and specific Debian and openSUSE releases.
What type of vulnerability is CVE-2016-8677?
CVE-2016-8677 is a memory allocation vulnerability found in the ImageMagick library.
Is there an upstream patch for CVE-2016-8677?
Yes, there is an upstream patch available for CVE-2016-8677 that addresses the memory allocation failure.