Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-8707

Опубликовано: 03 дек. 2016
Источник: redhat
CVSS3: 4.9
CVSS2: 4.4
EPSS Низкий

Описание

An exploitable out of bounds write exists in the handling of compressed TIFF images in ImageMagicks's convert utility. A crafted TIFF document can lead to an out of bounds write which in particular circumstances could be leveraged into remote code execution. The vulnerability can be triggered through any user controlled TIFF that is handled by this functionality.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ImageMagickNot affected
Red Hat Enterprise Linux 6ImageMagickWill not fix
Red Hat Enterprise Linux 7ImageMagickWill not fix
Red Hat OpenShift Enterprise 2ImageMagickWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1408375ImageMagick: OOB write in convert utility when deflating TIFF files

EPSS

Процентиль: 84%
0.02137
Низкий

4.9 Medium

CVSS3

4.4 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 9 лет назад

An exploitable out of bounds write exists in the handling of compressed TIFF images in ImageMagicks's convert utility. A crafted TIFF document can lead to an out of bounds write which in particular circumstances could be leveraged into remote code execution. The vulnerability can be triggered through any user controlled TIFF that is handled by this functionality.

CVSS3: 7.8
nvd
около 9 лет назад

An exploitable out of bounds write exists in the handling of compressed TIFF images in ImageMagicks's convert utility. A crafted TIFF document can lead to an out of bounds write which in particular circumstances could be leveraged into remote code execution. The vulnerability can be triggered through any user controlled TIFF that is handled by this functionality.

CVSS3: 7.8
debian
около 9 лет назад

An exploitable out of bounds write exists in the handling of compresse ...

CVSS3: 7
github
больше 3 лет назад

An exploitable out of bounds write exists in the handling of compressed TIFF images in ImageMagicks's convert utility. A crafted TIFF document can lead to an out of bounds write which in particular circumstances could be leveraged into remote code execution. The vulnerability can be triggered through any user controlled TIFF that is handled by this functionality.

suse-cvrf
около 9 лет назад

Security update for ImageMagick

EPSS

Процентиль: 84%
0.02137
Низкий

4.9 Medium

CVSS3

4.4 Medium

CVSS2