First published: Wed Feb 15 2017(Updated: )
The ReadPCXImage function in coders/pcx.c in GraphicsMagick 1.3.25 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory allocation failure and a "file truncation error for corrupt file."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick | =1.3.25 | |
openSUSE | =13.2 | |
Debian Linux | =8.0 | |
=1.3.25 | ||
=13.2 | ||
=8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8683 has a moderate severity level due to its potential to cause memory allocation failures.
To fix CVE-2016-8683, upgrade to a patched version of GraphicsMagick that addresses this vulnerability.
CVE-2016-8683 can lead to a memory allocation failure which may result in file truncation errors when processing crafted images.
CVE-2016-8683 affects GraphicsMagick version 1.3.25 and specific versions of Debian and openSUSE distributions.
Yes, remote attackers can exploit CVE-2016-8683 by sending specially crafted image files to trigger the vulnerabilities.