CVE-2016-8866: Buffer Overflow
It was discovered that the upstream fix for this issue was not complete. There is still a memory allocation failure in memory.c
References:
http://seclists.org/oss-sec/2016/q4/197 https://blogs.gentoo.org/ago/2016/10/20/imagemagick-memory-allocation-failure-in-acquiremagickmemory-memory-c-incomplete-fix-for-cve-2016-8862/
Other sources
The AcquireMagickMemory function in MagickCore/memory.c in ImageMagick 7.0.3.3 before 7.0.3.8 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory allocation failure. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8862.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8866?
The severity of CVE-2016-8866 is considered important due to the potential for memory allocation failures.
How do I fix CVE-2016-8866?
To fix CVE-2016-8866, you should upgrade to the latest version of ImageMagick that addresses this vulnerability.
What applications are affected by CVE-2016-8866?
Applications affected by CVE-2016-8866 include certain versions of ImageMagick and specific openSUSE releases.
Is CVE-2016-8866 related to any other vulnerabilities?
Yes, CVE-2016-8866 is related to CVE-2016-8862 as it pertains to a similar memory allocation issue.
How was CVE-2016-8866 discovered?
CVE-2016-8866 was discovered as part of an upstream fix that was incomplete, leading to a memory allocation failure.