CVE-2016-6491
Gentoo Linux Security Advisory 201611-21
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Buffer overflow in the Get8BIMProperty function in MagickCore/property.c in ImageMagick before 6.9.5-4 and 7.x before 7.0.2-6 allows remote attackers to cause a denial of service (out-of-bounds read, memory leak, and crash) via a crafted image.
Desbordamiento de búfer en la función Get8BIMProperty en MagickCore/property.c en ImageMagick en versiones anteriores a 6.9.5-4 y 7.x en versiones anteriores a 7.0.2-6 permite a atacantes remotos provocar una denegación de servicio (lectura fuera de límites, fuga de memoria y caída) a través de una imagen manipulada.
handling problems and cases of missing or incomplete input sanitising may result in denial of service or the execution of arbitrary code if malformed TIFF, WPG, RLE, RAW, PSD, Sun, PICT, VIFF, HDR, Meta, Quantum, PDB, DDS, DCM, EXIF, RGF or BMP files are processed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-07-28 CVE Reserved
- 2016-08-26 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-125: Out-of-bounds Read
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html | Third Party Advisory |
|
http://www.securityfocus.com/bid/92186 | Third Party Advisory | |
http://www.securitytracker.com/id/1036501 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
http://www.openwall.com/lists/oss-security/2016/07/28/13 | 2024-08-06 | |
http://www.openwall.com/lists/oss-security/2016/07/28/15 | 2024-08-06 |
URL | Date | SRC |
---|---|---|
https://github.com/ImageMagick/ImageMagick/commit/dd84447b63a71fa8c3f47071b09454efc667767b | 2017-07-01 |
URL | Date | SRC |
---|---|---|
https://github.com/ImageMagick/ImageMagick/blob/6.9.5-4/ChangeLog | 2017-07-01 | |
https://security.gentoo.org/glsa/201611-21 | 2017-07-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Imagemagick Search vendor "Imagemagick" | Imagemagick Search vendor "Imagemagick" for product "Imagemagick" | <= 6.9.5-3 Search vendor "Imagemagick" for product "Imagemagick" and version " <= 6.9.5-3" | - |
Affected
| ||||||
Imagemagick Search vendor "Imagemagick" | Imagemagick Search vendor "Imagemagick" for product "Imagemagick" | 7.0.1-0 Search vendor "Imagemagick" for product "Imagemagick" and version "7.0.1-0" | - |
Affected
| ||||||
Imagemagick Search vendor "Imagemagick" | Imagemagick Search vendor "Imagemagick" for product "Imagemagick" | 7.0.1-1 Search vendor "Imagemagick" for product "Imagemagick" and version "7.0.1-1" | - |
Affected
| ||||||
Imagemagick Search vendor "Imagemagick" | Imagemagick Search vendor "Imagemagick" for product "Imagemagick" | 7.0.1-2 Search vendor "Imagemagick" for product "Imagemagick" and version "7.0.1-2" | - |
Affected
| ||||||
Imagemagick Search vendor "Imagemagick" | Imagemagick Search vendor "Imagemagick" for product "Imagemagick" | 7.0.1-3 Search vendor "Imagemagick" for product "Imagemagick" and version "7.0.1-3" | - |
Affected
| ||||||
Imagemagick Search vendor "Imagemagick" | Imagemagick Search vendor "Imagemagick" for product "Imagemagick" | 7.0.1-4 Search vendor "Imagemagick" for product "Imagemagick" and version "7.0.1-4" | - |
Affected
| ||||||
Imagemagick Search vendor "Imagemagick" | Imagemagick Search vendor "Imagemagick" for product "Imagemagick" | 7.0.1-5 Search vendor "Imagemagick" for product "Imagemagick" and version "7.0.1-5" | - |
Affected
| ||||||
Imagemagick Search vendor "Imagemagick" | Imagemagick Search vendor "Imagemagick" for product "Imagemagick" | 7.0.1-6 Search vendor "Imagemagick" for product "Imagemagick" and version "7.0.1-6" | - |
Affected
| ||||||
Imagemagick Search vendor "Imagemagick" | Imagemagick Search vendor "Imagemagick" for product "Imagemagick" | 7.0.1-7 Search vendor "Imagemagick" for product "Imagemagick" and version "7.0.1-7" | - |
Affected
| ||||||
Imagemagick Search vendor "Imagemagick" | Imagemagick Search vendor "Imagemagick" for product "Imagemagick" | 7.0.1-8 Search vendor "Imagemagick" for product "Imagemagick" and version "7.0.1-8" | - |
Affected
| ||||||
Imagemagick Search vendor "Imagemagick" | Imagemagick Search vendor "Imagemagick" for product "Imagemagick" | 7.0.1-9 Search vendor "Imagemagick" for product "Imagemagick" and version "7.0.1-9" | - |
Affected
| ||||||
Imagemagick Search vendor "Imagemagick" | Imagemagick Search vendor "Imagemagick" for product "Imagemagick" | 7.0.1-10 Search vendor "Imagemagick" for product "Imagemagick" and version "7.0.1-10" | - |
Affected
| ||||||
Imagemagick Search vendor "Imagemagick" | Imagemagick Search vendor "Imagemagick" for product "Imagemagick" | 7.0.2-0 Search vendor "Imagemagick" for product "Imagemagick" and version "7.0.2-0" | - |
Affected
| ||||||
Imagemagick Search vendor "Imagemagick" | Imagemagick Search vendor "Imagemagick" for product "Imagemagick" | 7.0.2-1 Search vendor "Imagemagick" for product "Imagemagick" and version "7.0.2-1" | - |
Affected
| ||||||
Imagemagick Search vendor "Imagemagick" | Imagemagick Search vendor "Imagemagick" for product "Imagemagick" | 7.0.2-2 Search vendor "Imagemagick" for product "Imagemagick" and version "7.0.2-2" | - |
Affected
| ||||||
Imagemagick Search vendor "Imagemagick" | Imagemagick Search vendor "Imagemagick" for product "Imagemagick" | 7.0.2-3 Search vendor "Imagemagick" for product "Imagemagick" and version "7.0.2-3" | - |
Affected
| ||||||
Imagemagick Search vendor "Imagemagick" | Imagemagick Search vendor "Imagemagick" for product "Imagemagick" | 7.0.2-4 Search vendor "Imagemagick" for product "Imagemagick" and version "7.0.2-4" | - |
Affected
| ||||||
Imagemagick Search vendor "Imagemagick" | Imagemagick Search vendor "Imagemagick" for product "Imagemagick" | 7.0.2-5 Search vendor "Imagemagick" for product "Imagemagick" and version "7.0.2-5" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Solaris Search vendor "Oracle" for product "Solaris" | 10.0 Search vendor "Oracle" for product "Solaris" and version "10.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Solaris Search vendor "Oracle" for product "Solaris" | 11.3 Search vendor "Oracle" for product "Solaris" and version "11.3" | - |
Affected
|