CVE-2016-9773: Buffer Overflow
Published Feb 16, 2017
·Updated
Heap-based buffer overflow in the IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3.8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-9556.
Affected Software
1 affected component
ImageMagick=7.0.3-8
Remediation
Event History
Feb 16, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Feb 17, 2017
Data Sourced
via NVD·02:59 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-9773?
CVE-2016-9773 has a severity rating that indicates a significant risk of denial of service due to a heap-based buffer overflow.
2
How do I fix CVE-2016-9773?
To fix CVE-2016-9773, update ImageMagick to a version that is not vulnerable, specifically a version later than 7.0.3-8.
3
What systems are affected by CVE-2016-9773?
CVE-2016-9773 affects ImageMagick version 7.0.3-8.
4
What type of vulnerability is CVE-2016-9773?
CVE-2016-9773 is a heap-based buffer overflow vulnerability.
5
Can CVE-2016-9773 lead to code execution?
CVE-2016-9773 primarily leads to denial of service rather than direct code execution.