CVE-2016-8678: Buffer Overflow
A heap-buffer overflow vulnerability was found in ImageMagick in pixel-accessor.h.
References:
http://seclists.org/oss-sec/2016/q4/67 https://blogs.gentoo.org/ago/2016/10/07/imagemagick-heap-based-buffer-overflow-in-ispixelmonochrome-pixel-accessor-h/
Other sources
The IsPixelMonochrome function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3.0 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted file. NOTE: the vendor says "This is a Q64 issue and we do not support Q64."
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8678?
CVE-2016-8678 has a high severity rating due to the potential for remote code execution through a heap-buffer overflow.
How do I fix CVE-2016-8678?
To fix CVE-2016-8678, upgrade ImageMagick to version 7.0.3-1 or later.
What software is affected by CVE-2016-8678?
CVE-2016-8678 affects ImageMagick version 7.0.3-0.
Can CVE-2016-8678 lead to data corruption?
Yes, CVE-2016-8678 can potentially lead to data corruption if exploited.
What type of vulnerability is CVE-2016-8678?
CVE-2016-8678 is classified as a heap-buffer overflow vulnerability.