CVE-2016-8862: Buffer Overflow
A memory allocation failure was found in ImageMagick in memory.c
References:
http://seclists.org/oss-sec/2016/q4/167 https://blogs.gentoo.org/ago/2016/10/17/imagemagick-memory-allocation-failure-in-acquiremagickmemory-memory-c/
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/aea6c6507f55632829e6432f8177a084a57c9fcc
Other sources
The AcquireMagickMemory function in MagickCore/memory.c in ImageMagick before 7.0.3.3 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory allocation failure.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8862?
CVE-2016-8862 is classified as a moderate severity vulnerability due to its potential impact on memory management in ImageMagick.
How do I fix CVE-2016-8862?
To fix CVE-2016-8862, upgrade ImageMagick to version 7.0.3.3 or later, or if using version 6.x, ensure it is updated to any version above 6.9.4-0.
What are the affected versions for CVE-2016-8862?
CVE-2016-8862 affects ImageMagick versions prior to 7.0.3.3 and versions from 7.0.0-0 up to 7.0.3-3.
What causes CVE-2016-8862?
CVE-2016-8862 is caused by a memory allocation failure in the ImageMagick library.
Is CVE-2016-8862 present in Debian systems?
Yes, CVE-2016-8862 can affect Debian systems running ImageMagick versions before the patched releases.