CVE-2016-9298: Buffer Overflow
Heap overflow in the WaveletDenoiseImage function in MagickCore/fx.c in ImageMagick before 6.9.6-4 and 7.x before 7.0.3-6 allows remote attackers to cause a denial of service (crash) via a crafted image.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9298?
CVE-2016-9298 is classified as a denial of service vulnerability due to a heap overflow in the WaveletDenoiseImage function leading to application crashes.
How do I fix CVE-2016-9298?
To fix CVE-2016-9298, upgrade ImageMagick to version 6.9.6-4 or later for 6.x versions, or version 7.0.3-6 or later for 7.x versions.
What versions of ImageMagick are affected by CVE-2016-9298?
CVE-2016-9298 affects ImageMagick versions prior to 6.9.6-4 and all 7.x versions before 7.0.3-6.
How can attackers exploit CVE-2016-9298?
Attackers can exploit CVE-2016-9298 by sending crafted images to the ImageMagick processor, causing it to crash.
What are the implications of CVE-2016-9298?
The implications of CVE-2016-9298 include application crashes and potential service disruption due to the denial of service vulnerability.