Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-10062

Опубликовано: 02 мар. 2017
Источник: debian

Описание

The ReadGROUP4Image function in coders/tiff.c in ImageMagick does not check the return value of the fwrite function, which allows remote attackers to cause a denial of service (application crash) via a crafted file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
imagemagickfixed8:6.9.7.4+dfsg-1package

Примечания

  • https://github.com/ImageMagick/ImageMagick/issues/196

  • https://github.com/ImageMagick/ImageMagick/issues/352

  • https://www.openwall.com/lists/oss-security/2016/12/20/3

  • CVE is for the fwrite issue in ReadGROUP4Image. This was

  • specifically noted at the beginning of issues/196, but not fixed in

  • either of these commits 933e96f01a8c889c7bf5ffd30020e86a02a046e7 nor

  • 4e914bbe371433f0590cefdf3bd5f3a5710069f9 upstream. It is not the same

  • as the fputc issue in ReadGROUP4Image.

  • https://github.com/ImageMagick/ImageMagick/commit/41e955984b034777903cfa61e500a0b922eb9cbd

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 9 лет назад

The ReadGROUP4Image function in coders/tiff.c in ImageMagick does not check the return value of the fwrite function, which allows remote attackers to cause a denial of service (application crash) via a crafted file.

CVSS3: 3.3
redhat
больше 9 лет назад

The ReadGROUP4Image function in coders/tiff.c in ImageMagick does not check the return value of the fwrite function, which allows remote attackers to cause a denial of service (application crash) via a crafted file.

CVSS3: 5.5
nvd
почти 9 лет назад

The ReadGROUP4Image function in coders/tiff.c in ImageMagick does not check the return value of the fwrite function, which allows remote attackers to cause a denial of service (application crash) via a crafted file.

CVSS3: 5.5
github
больше 3 лет назад

The ReadGROUP4Image function in coders/tiff.c in ImageMagick does not check the return value of the fwrite function, which allows remote attackers to cause a denial of service (application crash) via a crafted file.

fstec
почти 9 лет назад

Уязвимость консольного графического редактора ImageMagick, позволяющая нарушителю вызвать отказ в обслуживании