First published: Thu Oct 20 2016(Updated: )
A memory allocation failure was found in ImageMagick in memory.c References: <a href="http://seclists.org/oss-sec/2016/q4/167">http://seclists.org/oss-sec/2016/q4/167</a> <a href="https://blogs.gentoo.org/ago/2016/10/17/imagemagick-memory-allocation-failure-in-acquiremagickmemory-memory-c/">https://blogs.gentoo.org/ago/2016/10/17/imagemagick-memory-allocation-failure-in-acquiremagickmemory-memory-c/</a> Upstream patch: <a href="https://github.com/ImageMagick/ImageMagick/commit/aea6c6507f55632829e6432f8177a084a57c9fcc">https://github.com/ImageMagick/ImageMagick/commit/aea6c6507f55632829e6432f8177a084a57c9fcc</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ImageMagick | <7.0.3.3 | 7.0.3.3 |
ImageMagick | <6.9.4-0 | |
ImageMagick | >=7.0.0-0<7.0.3-3 | |
Debian | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8862 is classified as a moderate severity vulnerability due to its potential impact on memory management in ImageMagick.
To fix CVE-2016-8862, upgrade ImageMagick to version 7.0.3.3 or later, or if using version 6.x, ensure it is updated to any version above 6.9.4-0.
CVE-2016-8862 affects ImageMagick versions prior to 7.0.3.3 and versions from 7.0.0-0 up to 7.0.3-3.
CVE-2016-8862 is caused by a memory allocation failure in the ImageMagick library.
Yes, CVE-2016-8862 can affect Debian systems running ImageMagick versions before the patched releases.