REDHAT-BUG-1398198: Buffer Overflow
A heap-buffer overflow vulnerability was found in ImageMagick in IsPixelGray function in pixel-accessor.h triggered by opening a malicious image.
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/ce98a7acbcfca7f0a178f4b1e7b957e419e0cc99
References:
http://seclists.org/oss-sec/2016/q4/469
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1398198?
The severity of REDHAT-BUG-1398198 is classified as critical due to the heap-buffer overflow vulnerability in ImageMagick.
How do I fix REDHAT-BUG-1398198?
To fix REDHAT-BUG-1398198, you should apply the latest patches or updates from ImageMagick that address this heap-buffer overflow issue.
What could happen if REDHAT-BUG-1398198 is exploited?
If REDHAT-BUG-1398198 is exploited, it could allow an attacker to execute arbitrary code on the affected system.
Which versions of ImageMagick are affected by REDHAT-BUG-1398198?
REDHAT-BUG-1398198 affects various versions of ImageMagick, so it is essential to review your specific version for vulnerability.
How can I determine if my system is vulnerable to REDHAT-BUG-1398198?
You can determine if your system is vulnerable to REDHAT-BUG-1398198 by checking the installed version of ImageMagick against the known vulnerable versions listed in release notes or advisories.