First published: Mon Dec 05 2016(Updated: )
A memory allocation failure was discovered in GraphicsMagick in MagickRealloc in memory.c References: <a href="http://seclists.org/oss-sec/2016/q4/586">http://seclists.org/oss-sec/2016/q4/586</a> <a href="https://blogs.gentoo.org/ago/2016/12/01/graphicsmagick-memory-allocation-failure-in-magickrealloc-memory-c">https://blogs.gentoo.org/ago/2016/12/01/graphicsmagick-memory-allocation-failure-in-magickrealloc-memory-c</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick | =1.3.25 | |
Debian | =8.0 | |
openSUSE | =42.1 | |
openSUSE | =42.2 | |
openSUSE | =13.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9830 has a medium severity rating due to its memory allocation failure that could lead to application crashes.
To fix CVE-2016-9830, upgrade GraphicsMagick to version 1.3.26 or later.
GraphicsMagick version 1.3.25 is vulnerable to CVE-2016-9830.
Yes, CVE-2016-9830 affects Debian GNU/Linux version 8.0 when using the vulnerable GraphicsMagick package.
CVE-2016-9830 can lead to application crashes which may be leveraged by attackers for denial of service.